Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-238c-73w3-x9m4

Опубликовано: 21 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user role, revealing the password requires to escape out of the MDM controlled device's profile.

Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user role, revealing the password requires to escape out of the MDM controlled device's profile.

EPSS

Процентиль: 7%
0.0003
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.5
nvd
17 дней назад

Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user role, revealing the password requires to escape out of the MDM controlled device's profile.

EPSS

Процентиль: 7%
0.0003
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862