Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-23g2-f757-4428

Опубликовано: 25 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.9

Описание

An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command.

This issue affects Fireware OS: from 12.0 before 12.11.2.

An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command.

This issue affects Fireware OS: from 12.0 before 12.11.2.

EPSS

Процентиль: 12%
0.0004
Низкий

8.9 High

CVSS4

Дефекты

CWE-489

Связанные уязвимости

nvd
12 дней назад

An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command. This issue affects Fireware OS: from 12.0 before 12.11.2.

EPSS

Процентиль: 12%
0.0004
Низкий

8.9 High

CVSS4

Дефекты

CWE-489