Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-88j9-xvhv-gwc6

Опубликовано: 07 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to version 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service.

Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to version 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service.

EPSS

Процентиль: 39%
0.00171
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-770

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 лет назад

Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service.

EPSS

Процентиль: 39%
0.00171
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-770