Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-866w-mhv5-886h

Опубликовано: 22 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

?A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to the device via a USB stick.

?A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to the device via a USB stick.

EPSS

Процентиль: 27%
0.00092
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-74
CWE-77

Связанные уязвимости

CVSS3: 6.8
nvd
больше 2 лет назад

​A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to the device via a USB stick.

EPSS

Процентиль: 27%
0.00092
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-74
CWE-77