Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4q3p-mjvg-jp72

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S5700 V200R019C00SPC500, S6700 V200R019C00SPC500 and S7700 V200R019C00SPC500. A module does not verify specific input sufficiently. Attackers can exploit this vulnerability by sending malicious parameters to inject command. This can compromise normal service.

There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S5700 V200R019C00SPC500, S6700 V200R019C00SPC500 and S7700 V200R019C00SPC500. A module does not verify specific input sufficiently. Attackers can exploit this vulnerability by sending malicious parameters to inject command. This can compromise normal service.

EPSS

Процентиль: 72%
0.00709
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.2
nvd
больше 4 лет назад

There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S5700 V200R019C00SPC500, S6700 V200R019C00SPC500 and S7700 V200R019C00SPC500. A module does not verify specific input sufficiently. Attackers can exploit this vulnerability by sending malicious parameters to inject command. This can compromise normal service.

EPSS

Процентиль: 72%
0.00709
Низкий

Дефекты

CWE-20