Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-953p-8577-4q9f

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the normal web administrative console for the 'user' account, the configuration file is accessible via direct object reference (DRO) at http:///goform/down_cfg_file by this otherwise low privilege 'user' account.

In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the normal web administrative console for the 'user' account, the configuration file is accessible via direct object reference (DRO) at http:///goform/down_cfg_file by this otherwise low privilege 'user' account.

EPSS

Процентиль: 97%
0.33387
Средний

8.8 High

CVSS3

Дефекты

CWE-472
CWE-732

Связанные уязвимости

CVSS3: 8.8
nvd
около 8 лет назад

In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the normal web administrative console for the 'user' account, the configuration file is accessible via direct object reference (DRO) at http://<device-ip-or-hostname>/goform/down_cfg_file by this otherwise low privilege 'user' account.

EPSS

Процентиль: 97%
0.33387
Средний

8.8 High

CVSS3

Дефекты

CWE-472
CWE-732