Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g789-9h8j-6whm

Опубликовано: 26 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Incorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows attackers to replace password hashes stored in the EEPROM with hashes of their own, leading to the escalation of privileges to root.

Incorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows attackers to replace password hashes stored in the EEPROM with hashes of their own, leading to the escalation of privileges to root.

EPSS

Процентиль: 26%
0.00092
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284
CWE-922

Связанные уязвимости

CVSS3: 6.8
nvd
6 месяцев назад

Incorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows attackers to replace password hashes stored in the EEPROM with hashes of their own, leading to the escalation of privileges to root.

EPSS

Процентиль: 26%
0.00092
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284
CWE-922