Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5vxj-c9wj-5m6q

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can be accessed without authentication, which may allow a remote attacker to perform sensitive functions including arbitrary file upload, file download, and device reboot.

An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can be accessed without authentication, which may allow a remote attacker to perform sensitive functions including arbitrary file upload, file download, and device reboot.

EPSS

Процентиль: 92%
0.0769
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-285
CWE-306

Связанные уязвимости

CVSS3: 9.8
nvd
больше 8 лет назад

An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can be accessed without authentication, which may allow a remote attacker to perform sensitive functions including arbitrary file upload, file download, and device reboot.

EPSS

Процентиль: 92%
0.0769
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-285
CWE-306