Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c4wm-h8mm-vr45

Опубликовано: 09 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application allows an attacker to add their own login credentials to the device. This allows an attacker to remotely login as root and take control of the device even after the affected device is fully set up.

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application allows an attacker to add their own login credentials to the device. This allows an attacker to remotely login as root and take control of the device even after the affected device is fully set up.

EPSS

Процентиль: 61%
0.00407
Низкий

8.8 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 лет назад

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application allows an attacker to add their own login credentials to the device. This allows an attacker to remotely login as root and take control of the device even after the affected device is fully set up.

CVSS3: 8.8
fstec
около 2 лет назад

Уязвимость процесса промежуточной установки микропрограммного обеспечения коммуникационного шлюза SIMATIC CN 4100, позволяющая нарушителю войти в систему и получить полный контроль над приложением

EPSS

Процентиль: 61%
0.00407
Низкий

8.8 High

CVSS3

Дефекты

CWE-639