Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fgx6-cf44-r3h2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected device.

ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected device.

EPSS

Процентиль: 82%
0.01816
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22
CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected device.

EPSS

Процентиль: 82%
0.01816
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22
CWE-434