Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5rmc-9cm9-28cr

Опубликовано: 25 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

A vulnerability has been found in H3C Magic NX30 Pro and Magic NX400 up to V100R014 and classified as critical. This vulnerability affects unknown code of the file /api/wizard/getNetworkConf. The manipulation leads to command injection. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.

A vulnerability has been found in H3C Magic NX30 Pro and Magic NX400 up to V100R014 and classified as critical. This vulnerability affects unknown code of the file /api/wizard/getNetworkConf. The manipulation leads to command injection. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 61%
0.00406
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 8
nvd
11 месяцев назад

A vulnerability has been found in H3C Magic NX30 Pro and Magic NX400 up to V100R014 and classified as critical. This vulnerability affects unknown code of the file /api/wizard/getNetworkConf. The manipulation leads to command injection. The attack needs to be approached within the local network. It is recommended to upgrade the affected component.

EPSS

Процентиль: 61%
0.00406
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-74