Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f2v4-c8r6-vfvj

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the integrity of the applications, which could allow remote attackers to install Trojan horse applications via DNS spoofing.

Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the integrity of the applications, which could allow remote attackers to install Trojan horse applications via DNS spoofing.

EPSS

Процентиль: 66%
0.00512
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 9.8
nvd
больше 23 лет назад

Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the integrity of the applications, which could allow remote attackers to install Trojan horse applications via DNS spoofing.

EPSS

Процентиль: 66%
0.00512
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-494