Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-697p-5m9w-jhmw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A hard-coded password vulnerability exists in the SFTP Log Collection Server function of Trend Micro Inc.’s Home Network Security 6.1.567. A specially crafted network request can lead to arbitrary authentication. An attacker can send an unauthenticated message to trigger this vulnerability.

A hard-coded password vulnerability exists in the SFTP Log Collection Server function of Trend Micro Inc.’s Home Network Security 6.1.567. A specially crafted network request can lead to arbitrary authentication. An attacker can send an unauthenticated message to trigger this vulnerability.

EPSS

Процентиль: 67%
0.00532
Низкий

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 6.5
nvd
больше 4 лет назад

Trend Micro Home Network Security version 6.6.604 and earlier contains a hard-coded password vulnerability in the log collection server which could allow an attacker to use a specially crafted network request to lead to arbitrary authentication. An attacker must first obtain the ability to execute high-privileged code on the target device in order to exploit this vulnerability.

EPSS

Процентиль: 67%
0.00532
Низкий

Дефекты

CWE-798