Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f2cq-m485-xq43

Опубликовано: 06 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

An attacker with access to the private network (the charger is connected to) or local access to the Ethernet-Interface can exploit a faulty implementation of the JWT-library in order to bypass the password authentication to the web configuration interface and then has full access as the user would have. However, an attacker will not have developer or admin rights. If the implementation of the JWT-library is wrongly configured to accept "none"-algorithms, the server will pass insecure JWT. A local, unauthenticated attacker can exploit this vulnerability to bypass the authentication mechanism.

An attacker with access to the private network (the charger is connected to) or local access to the Ethernet-Interface can exploit a faulty implementation of the JWT-library in order to bypass the password authentication to the web configuration interface and then has full access as the user would have. However, an attacker will not have developer or admin rights. If the implementation of the JWT-library is wrongly configured to accept "none"-algorithms, the server will pass insecure JWT. A local, unauthenticated attacker can exploit this vulnerability to bypass the authentication mechanism.

EPSS

Процентиль: 6%
0.00023
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 6.3
nvd
больше 1 года назад

An attacker with access to the private network (the charger is connected to) or local access to the Ethernet-Interface can exploit a faulty implementation of the JWT-library in order to bypass the password authentication to the web configuration interface and then has full access as the user would have. However, an attacker will not have developer or admin rights. If the implementation of the JWT-library is wrongly configured to accept "none"-algorithms, the server will pass insecure JWT. A local, unauthenticated attacker can exploit this vulnerability to bypass the authentication mechanism.

EPSS

Процентиль: 6%
0.00023
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-345