Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gqwx-q2cx-gx28

Опубликовано: 27 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. An attacker can obtain encrypted MQTT credentials by sending a specific crafted packet to the vulnerable interface (the credentials cannot be directly exploited).

Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. An attacker can obtain encrypted MQTT credentials by sending a specific crafted packet to the vulnerable interface (the credentials cannot be directly exploited).

EPSS

Процентиль: 33%
0.00133
Низкий

7.5 High

CVSS3

Дефекты

CWE-306
CWE-522

Связанные уязвимости

CVSS3: 7.5
nvd
около 3 лет назад

Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. An attacker can obtain encrypted MQTT credentials by sending a specific crafted packet to the vulnerable interface (the credentials cannot be directly exploited).

EPSS

Процентиль: 33%
0.00133
Низкий

7.5 High

CVSS3

Дефекты

CWE-306
CWE-522