Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8q86-4x73-99v8

Опубликовано: 26 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.

The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.

EPSS

Процентиль: 47%
0.00245
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1188
CWE-441

Связанные уязвимости

CVSS3: 6.5
nvd
почти 2 года назад

The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.

CVSS3: 9
fstec
почти 2 года назад

Уязвимость веб-службы микропрограммного обеспечения управляемых коммутаторов серий EDS-4000/G4000, позволяющая нарушителю отправлять запросы к уязвимому устройству и от его имени другим устройствам сети

EPSS

Процентиль: 47%
0.00245
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1188
CWE-441