Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g784-x97g-r6ww

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a denial of service and payload tampering.

Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a denial of service and payload tampering.

EPSS

Процентиль: 42%
0.00199
Низкий

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 5.9
nvd
больше 4 лет назад

Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a denial of service and payload tampering.

EPSS

Процентиль: 42%
0.00199
Низкий

Дефекты

CWE-295