Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2vv3-q2gp-2rjv

Опубликовано: 22 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests to sensitive endpoints as an unauthenticated user to perform critical actions or modify critical configuration parameters.

Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests to sensitive endpoints as an unauthenticated user to perform critical actions or modify critical configuration parameters.

EPSS

Процентиль: 54%
0.00319
Низкий

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 7.3
nvd
около 4 лет назад

Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests to sensitive endpoints as an unauthenticated user to perform critical actions or modify critical configuration parameters.

EPSS

Процентиль: 54%
0.00319
Низкий

Дефекты

CWE-798