Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7qcj-vcxv-7c7p

Опубликовано: 07 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of-Service (DoS). This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.302 for the LP series and 1.296 for the EP series. The attacker needs to have a properly signed and encrypted binary, loading the firmware to the device ultimately triggers a reboot.

An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of-Service (DoS). This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.302 for the LP series and 1.296 for the EP series. The attacker needs to have a properly signed and encrypted binary, loading the firmware to the device ultimately triggers a reboot.

EPSS

Процентиль: 58%
0.00368
Низкий

7.5 High

CVSS3

Дефекты

CWE-425

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of-Service (DoS). This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.302 for the LP series and 1.296 for the EP series. The attacker needs to have a properly signed and encrypted binary, loading the firmware to the device ultimately triggers a reboot.

CVSS3: 7.5
fstec
больше 3 лет назад

Уязвимость микропрограммного обеспечения программируемых логических контроллеров HID Mercury, связанная с ошибками механизмов безопасности, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 58%
0.00368
Низкий

7.5 High

CVSS3

Дефекты

CWE-425