Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-928h-v43x-jjq6

Опубликовано: 14 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import feature of the affected systems allow a privileged user to upload files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import feature of the affected systems allow a privileged user to upload files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.

EPSS

Процентиль: 85%
0.02408
Низкий

7.2 High

CVSS3

Дефекты

CWE-434
CWE-73

Связанные уязвимости

CVSS3: 7.2
nvd
больше 1 года назад

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import feature of the affected systems allow a privileged user to upload files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.

CVSS3: 7.2
fstec
больше 1 года назад

Уязвимость функции компонента Firmware Upload Handler системы безопасного управления доступом к IED Siemens RUGGEDCOM CROSSBOW, позволяющая нарушителю загрузить произвольные файлы и выполнить произвольный код

EPSS

Процентиль: 85%
0.02408
Низкий

7.2 High

CVSS3

Дефекты

CWE-434
CWE-73