Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fp3x-39wm-gj8f

Опубликовано: 07 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An unauthenticated attacker can send a specially crafted network packet to delete a user from the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.29. The impact of this vulnerability is that an unauthenticated attacker could restrict access to the web interface to legitimate users and potentially requiring them to use the default user dip switch procedure to gain access back.

An unauthenticated attacker can send a specially crafted network packet to delete a user from the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.29. The impact of this vulnerability is that an unauthenticated attacker could restrict access to the web interface to legitimate users and potentially requiring them to use the default user dip switch procedure to gain access back.

EPSS

Процентиль: 63%
0.00449
Низкий

7.5 High

CVSS3

Дефекты

CWE-425

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

An unauthenticated attacker can send a specially crafted network packet to delete a user from the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.29. The impact of this vulnerability is that an unauthenticated attacker could restrict access to the web interface to legitimate users and potentially requiring them to use the default user dip switch procedure to gain access back.

CVSS3: 7.5
fstec
больше 3 лет назад

Уязвимость микропрограммного обеспечения программируемых логических контроллеров HID Mercury, связанная с ошибками механизмов безопасности, позволяющая нарушителю удалить пользователя

EPSS

Процентиль: 63%
0.00449
Низкий

7.5 High

CVSS3

Дефекты

CWE-425