Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-96m4-wxp2-5cfp

Опубликовано: 23 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The affected devices contain a SUID binary that could allow an authenticated local attacker to execute arbitrary commands with root privileges.

A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The affected devices contain a SUID binary that could allow an authenticated local attacker to execute arbitrary commands with root privileges.

EPSS

Процентиль: 20%
0.00063
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 7.8
nvd
больше 1 года назад

A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The affected devices contain a SUID binary that could allow an authenticated local attacker to execute arbitrary commands with root privileges.

EPSS

Процентиль: 20%
0.00063
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-266