Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8rmv-qvj2-587v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to obtain a valid authentication token. Successful exploitation of this issue would result in the attacker being able to view and alter administrative configuration settings.

VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to obtain a valid authentication token. Successful exploitation of this issue would result in the attacker being able to view and alter administrative configuration settings.

EPSS

Процентиль: 50%
0.00265
Низкий

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.1
nvd
почти 5 лет назад

VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to obtain a valid authentication token. Successful exploitation of this issue would result in the attacker being able to view and alter administrative configuration settings.

CVSS3: 9.1
fstec
почти 5 лет назад

Уязвимость интерфейса администрирования облачной платформы обеспечения безопасности VMware Carbon Black Cloud Workload, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 50%
0.00265
Низкий

Дефекты

CWE-287