Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fvg3-mg3w-725q

Опубликовано: 11 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

A CWE-798: Use of Hard-coded Credentials vulnerability exists that could result in information disclosure. If an attacker were to obtain the SSH cryptographic key for the device and take active control of the local operational network connected to the product they could potentially observe and manipulate traffic associated with product configuration. Affected Product: Easergy P5 (All firmware versions prior to V01.401.101)

A CWE-798: Use of Hard-coded Credentials vulnerability exists that could result in information disclosure. If an attacker were to obtain the SSH cryptographic key for the device and take active control of the local operational network connected to the product they could potentially observe and manipulate traffic associated with product configuration. Affected Product: Easergy P5 (All firmware versions prior to V01.401.101)

EPSS

Процентиль: 37%
0.00158
Низкий

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

A CWE-798: Use of Hard-coded Credentials vulnerability exists that could result in information disclosure. If an attacker were to obtain the SSH cryptographic key for the device and take active control of the local operational network connected to the product they could potentially observe and manipulate traffic associated with product configuration. Affected Product: Easergy P5 (All firmware versions prior to V01.401.101)

CVSS3: 7.5
fstec
около 4 лет назад

Уязвимость микропрограммного обеспечения устройств релейной защиты и управления Schneider Electric Easergy P5, связанная с ошибками управления SSH-ключами, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 37%
0.00158
Низкий

Дефекты

CWE-798