Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2fr7-wcm8-348v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a stack-based buffer overflow to occur which could result in remote code execution when a malicious SSD file is uploaded and improperly parsed.

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a stack-based buffer overflow to occur which could result in remote code execution when a malicious SSD file is uploaded and improperly parsed.

EPSS

Процентиль: 80%
0.01384
Низкий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.8
nvd
около 5 лет назад

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a stack-based buffer overflow to occur which could result in remote code execution when a malicious SSD file is uploaded and improperly parsed.

CVSS3: 7.8
fstec
около 5 лет назад

Уязвимость программного обеспечения онлайн-конфигурации EcoStruxure Power Build, связанная с неограниченной загрузкой файлов опасного типа, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 80%
0.01384
Низкий

Дефекты

CWE-434