Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fv4f-72j5-c8mx

Опубликовано: 11 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.8
CVSS3: 7.3

Описание

Daikin Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An unauthorized attacker could access the system without prior credentials.

Daikin Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An unauthorized attacker could access the system without prior credentials.

EPSS

Процентиль: 35%
0.00146
Низкий

8.8 High

CVSS4

7.3 High

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 9.8
nvd
5 месяцев назад

Daikin Europe N.V Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An unauthorized attacker could access the system without prior credentials.

CVSS3: 9.8
fstec
5 месяцев назад

Уязвимость шлюза безопасности Daikin Security Gateway, связанная с недостатком механизма восстановления пароля, позволяющая нарушителю получить несанкционированный доступ к системе

EPSS

Процентиль: 35%
0.00146
Низкий

8.8 High

CVSS4

7.3 High

CVSS3

Дефекты

CWE-640