Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3wqf-jxw5-8w54

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in QSC Q-SYS Core Manager 8.2.1. By utilizing the TFTP service running on UDP port 69, a remote attacker can perform a directory traversal and obtain operating system files via a TFTP GET request, as demonstrated by reading /etc/passwd or /proc/version.

An issue was discovered in QSC Q-SYS Core Manager 8.2.1. By utilizing the TFTP service running on UDP port 69, a remote attacker can perform a directory traversal and obtain operating system files via a TFTP GET request, as demonstrated by reading /etc/passwd or /proc/version.

EPSS

Процентиль: 86%
0.0304
Низкий

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

An issue was discovered in QSC Q-SYS Core Manager 8.2.1. By utilizing the TFTP service running on UDP port 69, a remote attacker can perform a directory traversal and obtain operating system files via a TFTP GET request, as demonstrated by reading /etc/passwd or /proc/version.

EPSS

Процентиль: 86%
0.0304
Низкий

Дефекты

CWE-22