Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-89rj-8fq7-2vrc

Опубликовано: 30 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Patlite NH-FB v1.46 and below was discovered to contain insufficient firmware validation during the upgrade firmware file upload process. This vulnerability allows authenticated attackers to create and upload their own custom-built firmware and inject malicious code.

Patlite NH-FB v1.46 and below was discovered to contain insufficient firmware validation during the upgrade firmware file upload process. This vulnerability allows authenticated attackers to create and upload their own custom-built firmware and inject malicious code.

EPSS

Процентиль: 50%
0.00265
Низкий

8.8 High

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 8.8
nvd
больше 3 лет назад

Patlite NH-FB v1.46 and below was discovered to contain insufficient firmware validation during the upgrade firmware file upload process. This vulnerability allows authenticated attackers to create and upload their own custom-built firmware and inject malicious code. NOTE: the vendor's position is that this is a design choice, not a vulnerability

EPSS

Процентиль: 50%
0.00265
Низкий

8.8 High

CVSS3

Дефекты

CWE-345