Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2ggr-q5x3-fm96

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.4

Описание

A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device. This vulnerability is due to insufficient input validation for a specific command. An attacker could exploit this vulnerability by issuing a command with crafted arguments. A successful exploit could allow the attacker to overwrite or create files with data that is already present in other files that are hosted on the affected device.

A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device. This vulnerability is due to insufficient input validation for a specific command. An attacker could exploit this vulnerability by issuing a command with crafted arguments. A successful exploit could allow the attacker to overwrite or create files with data that is already present in other files that are hosted on the affected device.

EPSS

Процентиль: 21%
0.00069
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 4.4
nvd
почти 5 лет назад

A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device. This vulnerability is due to insufficient input validation for a specific command. An attacker could exploit this vulnerability by issuing a command with crafted arguments. A successful exploit could allow the attacker to overwrite or create files with data that is already present in other files that are hosted on the affected device.

CVSS3: 4.4
fstec
почти 5 лет назад

Уязвимость интерфейса командной строки микропрограммного обеспечения точек доступа Cisco Aironet Access Points, позволяющая нарушителю получить доступ на изменение, добавление или удаление данных

EPSS

Процентиль: 21%
0.00069
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-668