Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6fq2-7qrw-4c53

Опубликовано: 26 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute.

A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute.

EPSS

Процентиль: 24%
0.0008
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-281

Связанные уязвимости

CVSS3: 5.4
nvd
больше 2 лет назад

A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute.

EPSS

Процентиль: 24%
0.0008
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-281