Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9vqf-5jhj-hm4w

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in the hostname processing. A specially configured device hostname can cause the device to interpret selected remote traffic as local traffic, resulting in a bypass of web authentication. An attacker can send authenticated SNMP requests to trigger this vulnerability.

In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in the hostname processing. A specially configured device hostname can cause the device to interpret selected remote traffic as local traffic, resulting in a bypass of web authentication. An attacker can send authenticated SNMP requests to trigger this vulnerability.

EPSS

Процентиль: 63%
0.00445
Низкий

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7.2
nvd
больше 4 лет назад

In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in the hostname processing. A specially configured device hostname can cause the device to interpret selected remote traffic as local traffic, resulting in a bypass of web authentication. An attacker can send authenticated SNMP requests to trigger this vulnerability.

EPSS

Процентиль: 63%
0.00445
Низкий

Дефекты

CWE-287