Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fv2h-wg8w-37wh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A vulnerability has been identified in Desigo Insight (All versions). The device does not properly set the X-Frame-Options HTTP Header which makes it vulnerable to Clickjacking attacks. This could allow an unauthenticated attacker to retrieve or modify data in the context of a legitimate user by tricking that user to click on a website controlled by the attacker.

A vulnerability has been identified in Desigo Insight (All versions). The device does not properly set the X-Frame-Options HTTP Header which makes it vulnerable to Clickjacking attacks. This could allow an unauthenticated attacker to retrieve or modify data in the context of a legitimate user by tricking that user to click on a website controlled by the attacker.

EPSS

Процентиль: 56%
0.00333
Низкий

Дефекты

CWE-1021

Связанные уязвимости

CVSS3: 5.4
nvd
больше 5 лет назад

A vulnerability has been identified in Desigo Insight (All versions). The device does not properly set the X-Frame-Options HTTP Header which makes it vulnerable to Clickjacking attacks. This could allow an unauthenticated attacker to retrieve or modify data in the context of a legitimate user by tricking that user to click on a website controlled by the attacker.

CVSS3: 5.4
fstec
больше 5 лет назад

Уязвимость программного обеспечения для управления зданиями Desigo Insight, связанная с некорректным ограничением визуализируемых слоев пользовательского интерфейса, позволяющая нарушителю перенаправить пользователя на произвольный сайт

EPSS

Процентиль: 56%
0.00333
Низкий

Дефекты

CWE-1021