Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9jpf-vg83-7m3q

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server resource.

Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server resource.

EPSS

Процентиль: 47%
0.00239
Низкий

7.5 High

CVSS3

Дефекты

CWE-306
CWE-522

Связанные уязвимости

CVSS3: 8.6
nvd
больше 4 лет назад

Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server resource.

EPSS

Процентиль: 47%
0.00239
Низкий

7.5 High

CVSS3

Дефекты

CWE-306
CWE-522