Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fj8w-49wh-xf78

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed login attempt occurs. The file can be reached via an HTTP request. The credentials can be used to access the system via SSH (or TELNET if it is enabled).

ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed login attempt occurs. The file can be reached via an HTTP request. The credentials can be used to access the system via SSH (or TELNET if it is enabled).

EPSS

Процентиль: 68%
0.00563
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 9.8
nvd
почти 8 лет назад

ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed login attempt occurs. The file can be reached via an HTTP request. The credentials can be used to access the system via SSH (or TELNET if it is enabled).

EPSS

Процентиль: 68%
0.00563
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-522