Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5q6w-q4p8-f56h

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.3

Описание

The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows remote attackers to obtain administrative access via a command, as demonstrated by the addUserAndGroup action.

The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows remote attackers to obtain administrative access via a command, as demonstrated by the addUserAndGroup action.

EPSS

Процентиль: 48%
0.00246
Низкий

8.3 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.3
nvd
около 10 лет назад

The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows remote attackers to obtain administrative access via a command, as demonstrated by the addUserAndGroup action.

fstec
около 10 лет назад

Уязвимость программного средства для управления устройствами в сетях OnCell Central Manager, позволяющая нарушителю получить права администратора

EPSS

Процентиль: 48%
0.00246
Низкий

8.3 High

CVSS3

Дефекты

CWE-287