Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-75hv-856g-q3wx

Опубликовано: 06 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

A CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause legitimate users to be locked out of devices or facilitate backdoor account creation by spoofing a device on the local network. Affected Products: EcoStruxure™ Cybersecurity Admin Expert (CAE) (Versions prior to 2.2)

A CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause legitimate users to be locked out of devices or facilitate backdoor account creation by spoofing a device on the local network. Affected Products: EcoStruxure™ Cybersecurity Admin Expert (CAE) (Versions prior to 2.2)

EPSS

Процентиль: 30%
0.00113
Низкий

8.1 High

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 8
nvd
около 3 лет назад

A CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause legitimate users to be locked out of devices or facilitate backdoor account creation by spoofing a device on the local network. Affected Products: EcoStruxure™ Cybersecurity Admin Expert (CAE) (Versions prior to 2.2)

CVSS3: 8
fstec
больше 3 лет назад

Уязвимость программного средства администрирования безопасности Schneider Electric EcoStruxure Cybersecurity Admin Expert (CAE), связанная с обходом аутентификации посредством спуфинга, позволяющая нарушителю проводить спуфинг-атаки

EPSS

Процентиль: 30%
0.00113
Низкий

8.1 High

CVSS3

Дефекты

CWE-290