Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-246w-4q6g-jh9h

Опубликовано: 05 мая 2022
Источник: github
Github: Не прошло ревью

Описание

MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to (1) update the firmware via the squashfs parameter to upgrade_step2.sh or (2) obtain hashed passwords via the cgi-bin/cmh/backup.sh page.

MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to (1) update the firmware via the squashfs parameter to upgrade_step2.sh or (2) obtain hashed passwords via the cgi-bin/cmh/backup.sh page.

EPSS

Процентиль: 92%
0.07944
Низкий

Связанные уязвимости

CVSS3: 8.1
nvd
почти 6 лет назад

MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to (1) update the firmware via the squashfs parameter to upgrade_step2.sh or (2) obtain hashed passwords via the cgi-bin/cmh/backup.sh page.

EPSS

Процентиль: 92%
0.07944
Низкий