Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9jw6-h58q-m3jf

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets.

Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets.

EPSS

Процентиль: 36%
0.00148
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 5.9
nvd
около 7 лет назад

Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets.

EPSS

Процентиль: 36%
0.00148
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-798