Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fv86-7h6v-h3qg

Опубликовано: 05 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

The ACEManager component of ALEOS 4.16 and earlier does not

validate uploaded file names and types, which could potentially allow

an authenticated user to perform client-side script execution within

ACEManager, altering the device functionality until the device is

restarted.

The ACEManager component of ALEOS 4.16 and earlier does not

validate uploaded file names and types, which could potentially allow

an authenticated user to perform client-side script execution within

ACEManager, altering the device functionality until the device is

restarted.

EPSS

Процентиль: 0%
0.00004
Низкий

7.1 High

CVSS3

Дефекты

CWE-434
CWE-79

Связанные уязвимости

CVSS3: 7.1
nvd
около 2 лет назад

The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which could potentially allow an authenticated user to perform client-side script execution within ACEManager, altering the device functionality until the device is restarted.

CVSS3: 7.1
fstec
больше 2 лет назад

Уязвимость компонента ACEManager операционной системы ALEOS беспроводных маршрутизаторов Sierra Wireless MP70, RV50x, RV55, LX40, LX60 ES450, GX450, позволяющая нарушителю выполнить произвольные сценарии и вызвать перезагрузку устройства

EPSS

Процентиль: 0%
0.00004
Низкий

7.1 High

CVSS3

Дефекты

CWE-434
CWE-79