Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8rv9-5fv4-653w

Опубликовано: 25 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 7.2

Описание

Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an authenticated attacker with admin or report manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0.

Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an authenticated attacker with admin or report manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0.

EPSS

Процентиль: 64%
0.00477
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.2
nvd
почти 4 года назад

Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an authenticated attacker with admin or report manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0.

EPSS

Процентиль: 64%
0.00477
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-20