Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4f3p-5vq4-2r5c

Опубликовано: 11 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management Server (SMS). This allows an unauthenticated remote attacker to upload arbitrary files to the SMS host.

A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management Server (SMS). This allows an unauthenticated remote attacker to upload arbitrary files to the SMS host.

EPSS

Процентиль: 87%
0.03167
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22
CWE-24

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management Server (SMS). This allows an unauthenticated remote attacker to upload arbitrary files to the SMS host.

EPSS

Процентиль: 87%
0.03167
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22
CWE-24