Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3r22-jvx3-7mjc

Опубликовано: 06 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a specially crafted file on the target machine, which may give the attacker the ability to execute arbitrary code during the installation process initiated by a valid user. Affected Products: Easergy Builder Installer (1.7.23 and prior)

A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a specially crafted file on the target machine, which may give the attacker the ability to execute arbitrary code during the installation process initiated by a valid user. Affected Products: Easergy Builder Installer (1.7.23 and prior)

EPSS

Процентиль: 22%
0.00074
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 6.3
nvd
почти 3 года назад

A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a specially crafted file on the target machine, which may give the attacker the ability to execute arbitrary code during the installation process initiated by a valid user. Affected Products: Easergy Builder Installer (1.7.23 and prior)

CVSS3: 6.3
fstec
почти 3 года назад

Уязвимость программного средства для настройки контроллеров Schneider Electric Easergy Builder, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 22%
0.00074
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-427