Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8cf9-98r3-x57p

Опубликовано: 25 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

A vulnerability was determined in Topaz SERVCore Teller 2.14.0-RC2/2.14.1. Affected by this issue is some unknown functionality of the file SERVCoreTeller_2.0.40D.msi of the component Installer. Executing manipulation can lead to permission issues. The attack needs to be launched locally. The vendor was contacted early about this disclosure but did not respond in any way.

A vulnerability was determined in Topaz SERVCore Teller 2.14.0-RC2/2.14.1. Affected by this issue is some unknown functionality of the file SERVCoreTeller_2.0.40D.msi of the component Installer. Executing manipulation can lead to permission issues. The attack needs to be launched locally. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 4%
0.0002
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 7.8
nvd
5 месяцев назад

A vulnerability was determined in Topaz SERVCore Teller 2.14.0-RC2/2.14.1. Affected by this issue is some unknown functionality of the file SERVCoreTeller_2.0.40D.msi of the component Installer. Executing manipulation can lead to permission issues. The attack needs to be launched locally. You should upgrade the affected component. The vendor explains, that "this vulnerability was detected at the beginning of 2025, it was remediated because the latest published version of the installer no longer uses "nssm," which is responsible for this vulnerability".

EPSS

Процентиль: 4%
0.0002
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-266