Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f64w-hg82-2rqv

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attackers to cause a denial of service (reboot or shutdown), create arbitrary users, or possibly have unspecified other impact via a crafted request, as demonstrated by a beckhoff.com:service:cxconfig:1#Write SOAP action to /upnpisapi.

Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attackers to cause a denial of service (reboot or shutdown), create arbitrary users, or possibly have unspecified other impact via a crafted request, as demonstrated by a beckhoff.com:service:cxconfig:1#Write SOAP action to /upnpisapi.

EPSS

Процентиль: 79%
0.01214
Низкий

Дефекты

CWE-284

Связанные уязвимости

nvd
больше 10 лет назад

Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attackers to cause a denial of service (reboot or shutdown), create arbitrary users, or possibly have unspecified other impact via a crafted request, as demonstrated by a beckhoff.com:service:cxconfig:1#Write SOAP action to /upnpisapi.

EPSS

Процентиль: 79%
0.01214
Низкий

Дефекты

CWE-284