Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cc72-grgq-wvmx

Опубликовано: 26 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder and changing user’s passwords.

An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder and changing user’s passwords.

EPSS

Процентиль: 69%
0.0061
Низкий

7.5 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7.5
nvd
почти 4 года назад

An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder and changing user’s passwords.

EPSS

Процентиль: 69%
0.0061
Низкий

7.5 High

CVSS3

Дефекты

CWE-287