Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9x8w-8g8p-2qgx

Опубликовано: 11 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

otris Update Manager 1.2.1.0 allows local users to achieve SYSTEM access via unauthenticated calls to exposed interfaces over a .NET named pipe. A remote attack may be possible as well, by leveraging WsHTTPBinding for HTTP traffic on TCP port 9000.

otris Update Manager 1.2.1.0 allows local users to achieve SYSTEM access via unauthenticated calls to exposed interfaces over a .NET named pipe. A remote attack may be possible as well, by leveraging WsHTTPBinding for HTTP traffic on TCP port 9000.

EPSS

Процентиль: 11%
0.00039
Низкий

7.8 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7.8
nvd
почти 4 года назад

otris Update Manager 1.2.1.0 allows local users to achieve SYSTEM access via unauthenticated calls to exposed interfaces over a .NET named pipe. A remote attack may be possible as well, by leveraging WsHTTPBinding for HTTP traffic on TCP port 9000.

EPSS

Процентиль: 11%
0.00039
Низкий

7.8 High

CVSS3

Дефекты

CWE-287