Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-59cr-f2p3-c96w

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

EPSS

Процентиль: 100%
0.92752
Критический

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
больше 5 лет назад

rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

EPSS

Процентиль: 100%
0.92752
Критический

Дефекты

CWE-89