Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-94m6-39r7-r5v7

Опубликовано: 28 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12.1.4, and 12.5.10 allows an authenticated remote attacker with unprivileged credentials to upload or read files to limited, arbitrary locations on WatchGuard Firebox and XTM appliances

An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12.1.4, and 12.5.10 allows an authenticated remote attacker with unprivileged credentials to upload or read files to limited, arbitrary locations on WatchGuard Firebox and XTM appliances

EPSS

Процентиль: 52%
0.0029
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-88

Связанные уязвимости

CVSS3: 6.5
nvd
около 1 года назад

An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12.1.4, and 12.5.10 allows an authenticated remote attacker with unprivileged credentials to upload or read files to limited, arbitrary locations on WatchGuard Firebox and XTM appliances

EPSS

Процентиль: 52%
0.0029
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-88