Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9q6m-jvw2-h293

Опубликовано: 26 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited remotely leveraging a rogue Wi-Fi access point with a malicious SSID.

A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited remotely leveraging a rogue Wi-Fi access point with a malicious SSID.

EPSS

Процентиль: 24%
0.00079
Низкий

7.3 High

CVSS3

Дефекты

CWE-78
CWE-79

Связанные уязвимости

CVSS3: 7.3
nvd
около 1 года назад

A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited remotely leveraging a rogue Wi-Fi access point with a malicious SSID.

CVSS3: 7.3
fstec
больше 1 года назад

Уязвимость микропрограммного обеспечения многофункциональных беспроводных точек доступа Advantech EKI-6333AC-2G, EKI-6333AC-2GD и EKI-6333AC-1GPO, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 24%
0.00079
Низкий

7.3 High

CVSS3

Дефекты

CWE-78
CWE-79