Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-78gv-jfcm-9w8v

Опубликовано: 21 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TCP port 12304. An attacker with network access to this port can use weak hardcoded credentials to login to the FTP server and modify or read data, log files and gain remote code execution as NT Authority\SYSTEM on the server by exchanging accessible service binaries in the WorkExaminer installation directory (e.g. "C:\Program File (x86)\Work Examiner Professional Server").

The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TCP port 12304. An attacker with network access to this port can use weak hardcoded credentials to login to the FTP server and modify or read data, log files and gain remote code execution as NT Authority\SYSTEM on the server by exchanging accessible service binaries in the WorkExaminer installation directory (e.g. "C:\Program File (x86)\Work Examiner Professional Server").

EPSS

Процентиль: 55%
0.00321
Низкий

8.8 High

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 8.8
nvd
4 месяца назад

The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TCP port 12304. An attacker with network access to this port can use weak hardcoded credentials to login to the FTP server and modify or read data, log files and gain remote code execution as NT Authority\SYSTEM on the server by exchanging accessible service binaries in the WorkExaminer installation directory (e.g. "C:\Program File (x86)\Work Examiner Professional Server").

EPSS

Процентиль: 55%
0.00321
Низкий

8.8 High

CVSS3

Дефекты

CWE-798