Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gpf7-58jv-mggq

Опубликовано: 05 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

When configured in debugging mode by an authenticated user with

administrative privileges, ALEOS 4.16 and earlier store the SHA512

hash of the common root password for that version in a directory

accessible to a user with root privileges or equivalent access.

When configured in debugging mode by an authenticated user with

administrative privileges, ALEOS 4.16 and earlier store the SHA512

hash of the common root password for that version in a directory

accessible to a user with root privileges or equivalent access.

EPSS

Процентиль: 3%
0.00015
Низкий

8.1 High

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 8.1
nvd
около 2 лет назад

When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and earlier store the SHA512 hash of the common root password for that version in a directory accessible to a user with root privileges or equivalent access.

CVSS3: 8.1
fstec
больше 2 лет назад

Уязвимость режима отладки операционной системы ALEOS беспроводных маршрутизаторов Sierra Wireless MP70, RV50x, RV55, LX40, LX60 ES450, GX450, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 3%
0.00015
Низкий

8.1 High

CVSS3

Дефекты

CWE-798