Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4hrx-7xj9-j6h2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Baxter ExactaMix EM 2400 Versions 1.10, 1.11, and 1.13 and ExactaMix EM1200 Versions 1.1, 1.2, and 1.4 does not restrict non administrative users from gaining access to the operating system and editing the application startup script. Successful exploitation of this vulnerability may allow an attacker to alter the startup script as the limited-access user.

Baxter ExactaMix EM 2400 Versions 1.10, 1.11, and 1.13 and ExactaMix EM1200 Versions 1.1, 1.2, and 1.4 does not restrict non administrative users from gaining access to the operating system and editing the application startup script. Successful exploitation of this vulnerability may allow an attacker to alter the startup script as the limited-access user.

EPSS

Процентиль: 17%
0.00055
Низкий

Связанные уязвимости

CVSS3: 6.1
nvd
больше 5 лет назад

Baxter ExactaMix EM 2400 Versions 1.10, 1.11, and 1.13 and ExactaMix EM1200 Versions 1.1, 1.2, and 1.4 does not restrict non administrative users from gaining access to the operating system and editing the application startup script. Successful exploitation of this vulnerability may allow an attacker to alter the startup script as the limited-access user.

EPSS

Процентиль: 17%
0.00055
Низкий