Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4q7q-6wxm-5v68

Опубликовано: 23 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device to an attacker-controlled machine which serves the manipulated firmware file. The device is updated with the manipulated firmware.

Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device to an attacker-controlled machine which serves the manipulated firmware file. The device is updated with the manipulated firmware.

EPSS

Процентиль: 34%
0.00135
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-354

Связанные уязвимости

CVSS3: 5.4
nvd
около 2 лет назад

Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device to an attacker-controlled machine which serves the manipulated firmware file. The device is updated with the manipulated firmware.

EPSS

Процентиль: 34%
0.00135
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-354