Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3f6j-24pw-57fm

Опубликовано: 24 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to the admin console using default credentials, upload a malicious Java archive as a web service, and execute arbitrary commands on the host via SOAP requests to the deployed service.

BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to the admin console using default credentials, upload a malicious Java archive as a web service, and execute arbitrary commands on the host via SOAP requests to the deployed service.

EPSS

Процентиль: 43%
0.0054
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-1188

Связанные уязвимости

CVSS3: 9.8
nvd
4 месяца назад

BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to the admin console using default credentials, upload a malicious Java archive as a web service, and execute arbitrary commands on the host via SOAP requests to the deployed service.

EPSS

Процентиль: 43%
0.0054
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-1188