Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fhpq-7g7c-xh6j

Опубликовано: 28 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to bypass security constraints via unspecified vectors.

Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to bypass security constraints via unspecified vectors.

EPSS

Процентиль: 58%
0.00371
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-129

Связанные уязвимости

CVSS3: 5.4
nvd
почти 2 года назад

Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors.

EPSS

Процентиль: 58%
0.00371
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-129