Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-63fr-hqmm-7x7r

Опубликовано: 24 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 3.1

Описание

Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and inject malicious content into logs that compromise logs integrity. A malicious attacker could also prevent the product from logging information while malicious actions are performed or implicate an arbitrary user for malicious activities.

Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and inject malicious content into logs that compromise logs integrity. A malicious attacker could also prevent the product from logging information while malicious actions are performed or implicate an arbitrary user for malicious activities.

EPSS

Процентиль: 36%
0.00155
Низкий

3.1 Low

CVSS3

Дефекты

CWE-116
CWE-117

Связанные уязвимости

CVSS3: 3.1
nvd
около 2 лет назад

Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and inject malicious content into logs that compromise logs integrity. A malicious attacker could also prevent the product from logging information while malicious actions are performed or implicate an arbitrary user for malicious activities.

EPSS

Процентиль: 36%
0.00155
Низкий

3.1 Low

CVSS3

Дефекты

CWE-116
CWE-117