Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-95jv-r6j9-p8xr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Device42 Main Appliance before 17.05.01 does not sanitize user input in its Nmap Discovery utility. An attacker (with permissions to add or edit jobs run by this utility) can inject an extra argument to overwrite arbitrary files as the root user on the Remote Collector.

The Device42 Main Appliance before 17.05.01 does not sanitize user input in its Nmap Discovery utility. An attacker (with permissions to add or edit jobs run by this utility) can inject an extra argument to overwrite arbitrary files as the root user on the Remote Collector.

EPSS

Процентиль: 70%
0.00653
Низкий

Дефекты

CWE-88

Связанные уязвимости

CVSS3: 8.1
nvd
больше 4 лет назад

The Device42 Main Appliance before 17.05.01 does not sanitize user input in its Nmap Discovery utility. An attacker (with permissions to add or edit jobs run by this utility) can inject an extra argument to overwrite arbitrary files as the root user on the Remote Collector.

EPSS

Процентиль: 70%
0.00653
Низкий

Дефекты

CWE-88