Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2mwg-fg86-hrm4

Опубликовано: 19 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.2
CVSS3: 8.1

Описание

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSerialPort functionality to modify relevant device properties (such as serial interface settings), contradicting the security model proposed in the user manual.

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSerialPort functionality to modify relevant device properties (such as serial interface settings), contradicting the security model proposed in the user manual.

EPSS

Процентиль: 27%
0.00098
Низкий

7.2 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 8.1
nvd
5 месяцев назад

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSerialPort functionality to modify relevant device properties (such as serial interface settings), contradicting the security model proposed in the user manual.

EPSS

Процентиль: 27%
0.00098
Низкий

7.2 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-732