Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4m4r-x763-43q2

Опубликовано: 25 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and perform authenticated actions.

Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and perform authenticated actions.

EPSS

Процентиль: 85%
0.02629
Низкий

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and perform authenticated actions.

CVSS3: 9.8
fstec
больше 4 лет назад

Уязвимость исполняемого файла EarthAgent.exe средств защиты серверов и систем хранения ServerProtect for Storage (SPFS), ServerProtect for EMC Celerra (SPEMC), ServerProtect for Network Appliance Filers (SPNAF) и ServerProtect for Microsoft Windows/Novell Netware (SPNT), позволяющая нарушителю выполнить произвольные действия

EPSS

Процентиль: 85%
0.02629
Низкий

Дефекты

CWE-798