Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g33f-w5h5-7xvg

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution.

Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution.

EPSS

Процентиль: 11%
0.00038
Низкий

Связанные уязвимости

CVSS3: 7.8
nvd
около 6 лет назад

Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution.

EPSS

Процентиль: 11%
0.00038
Низкий