Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-59xf-p9qw-6vmh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured assets without proper authentication. This could be used by unauthorized parties to get configured login credentials of the assets via a modified pAccountID value.

Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured assets without proper authentication. This could be used by unauthorized parties to get configured login credentials of the assets via a modified pAccountID value.

EPSS

Процентиль: 59%
0.00378
Низкий

7.5 High

CVSS3

Дефекты

CWE-306
CWE-922

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured assets without proper authentication. This could be used by unauthorized parties to get configured login credentials of the assets via a modified pAccountID value. NOTE: The vendor has indicated this is not a vulnerability and states "This vulnerability occurred due to wrong configuration of system.

EPSS

Процентиль: 59%
0.00378
Низкий

7.5 High

CVSS3

Дефекты

CWE-306
CWE-922