Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-86vm-3wjc-w52p

Опубликовано: 06 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.9

Описание

An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system command along with a backup configuration, which could result in the execution of unwanted commands. This issue affects OneWireless all versions up to 322.1 and fixed in version 322.2.

An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system command along with a backup configuration, which could result in the execution of unwanted commands. This issue affects OneWireless all versions up to 322.1 and fixed in version 322.2.

EPSS

Процентиль: 9%
0.00031
Низкий

6.9 Medium

CVSS3

Дефекты

CWE-77
CWE-78

Связанные уязвимости

CVSS3: 6.9
nvd
больше 2 лет назад

An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system command along with a backup configuration, which could result in the execution of unwanted commands. This issue affects OneWireless all versions up to 322.1 and fixed in version 322.2.

CVSS3: 9.8
fstec
больше 2 лет назад

Уязвимость диспетчера беспроводных устройств Honeywell OneWireless Wireless Device Manager (WDM), связанная с непринятием мер по чистке данных на управляющем уровне, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 9%
0.00031
Низкий

6.9 Medium

CVSS3

Дефекты

CWE-77
CWE-78