Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g8wq-427w-wgqm

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software packages downloaded via an unprotected communication channel. This could allow a remote attacker to manipulate the software package while performing a Man-in-the-Middle (MitM) attack.

Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software packages downloaded via an unprotected communication channel. This could allow a remote attacker to manipulate the software package while performing a Man-in-the-Middle (MitM) attack.

EPSS

Процентиль: 34%
0.00138
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-345
CWE-494

Связанные уязвимости

CVSS3: 5.9
nvd
около 8 лет назад

Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software packages downloaded via an unprotected communication channel. This could allow a remote attacker to manipulate the software package while performing a Man-in-the-Middle (MitM) attack.

EPSS

Процентиль: 34%
0.00138
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-345
CWE-494