Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cjxj-wrcr-j6p4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable to file path injection. This enables the Attacker to write files with superuser privileges in specific locations.

An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable to file path injection. This enables the Attacker to write files with superuser privileges in specific locations.

EPSS

Процентиль: 57%
0.00346
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-732
CWE-94

Связанные уязвимости

CVSS3: 9.8
nvd
больше 6 лет назад

An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable to file path injection. This enables the Attacker to write files with superuser privileges in specific locations.

EPSS

Процентиль: 57%
0.00346
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-732
CWE-94