Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6rjf-jv9r-jj4v

Опубликовано: 06 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, which could allow an attacker to retrieve any file from the “RunningConfigs” directory. The attacker could then view and modify configuration files such as UserListInfo.xml, which would allow them to see existing administrative passwords.

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, which could allow an attacker to retrieve any file from the “RunningConfigs” directory. The attacker could then view and modify configuration files such as UserListInfo.xml, which would allow them to see existing administrative passwords.

EPSS

Процентиль: 49%
0.00261
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, which could allow an attacker to retrieve any file from the “RunningConfigs” directory. The attacker could then view and modify configuration files such as UserListInfo.xml, which would allow them to see existing administrative passwords.

EPSS

Процентиль: 49%
0.00261
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-306