Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6g22-rpp3-9gm7

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021.

When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021.

EPSS

Процентиль: 34%
0.00135
Низкий

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021.

EPSS

Процентиль: 34%
0.00135
Низкий

Дефекты

CWE-319