Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3g7f-9cp4-6m47

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and prior versions. An improper authentication vulnerability has been identified, which, if exploited, would allow an attacker with the same IP address to bypass authentication by accessing a specific uniform resource locator.

An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and prior versions. An improper authentication vulnerability has been identified, which, if exploited, would allow an attacker with the same IP address to bypass authentication by accessing a specific uniform resource locator.

EPSS

Процентиль: 81%
0.01493
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-290

Связанные уязвимости

CVSS3: 9.8
nvd
больше 8 лет назад

An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and prior versions. An improper authentication vulnerability has been identified, which, if exploited, would allow an attacker with the same IP address to bypass authentication by accessing a specific uniform resource locator.

EPSS

Процентиль: 81%
0.01493
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-290