Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gpv9-mf3p-h34x

Опубликовано: 25 нояб. 2021
Источник: github
Github: Не прошло ревью

Описание

Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to obtain sensitive information via a specially crafted web page.

Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to obtain sensitive information via a specially crafted web page.

EPSS

Процентиль: 56%
0.00338
Низкий

Дефекты

CWE-116

Связанные уязвимости

CVSS3: 5.7
nvd
около 4 лет назад

Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to obtain sensitive information via a specially crafted web page.

EPSS

Процентиль: 56%
0.00338
Низкий

Дефекты

CWE-116