Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2jx2-cgj2-48wc

Опубликовано: 23 мая 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 6.8

Описание

Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access these network devices, and modify their configurations. An attacker may also gain access to the host running the Device Installer software or the password hash of the user running the application.

Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access these network devices, and modify their configurations. An attacker may also gain access to the host running the Device Installer software or the password hash of the user running the application.

EPSS

Процентиль: 4%
0.00019
Низкий

6.9 Medium

CVSS4

6.8 Medium

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 6.8
nvd
9 месяцев назад

Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access these network devices, and modify their configurations. An attacker may also gain access to the host running the Device Installer software or the password hash of the user running the application.

EPSS

Процентиль: 4%
0.00019
Низкий

6.9 Medium

CVSS4

6.8 Medium

CVSS3

Дефекты

CWE-611