Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h8r9-fvmc-wrrc

Опубликовано: 29 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A successful exploit could allow the attacker to extract the root and admin password.

F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A successful exploit could allow the attacker to extract the root and admin password.

EPSS

Процентиль: 97%
0.35846
Средний

9.8 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
nvd
почти 2 года назад

F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A successful exploit could allow the attacker to extract the root and admin password.

CVSS3: 7.5
fstec
почти 2 года назад

Уязвимость микропрограммного обеспечения терминальной измерительной системы для систем выработки электроэнергии F-logic DataCube3, связанная с недостатками контроля доступа, позволяющая нарушителю получить пароли учетных записей root и admin

EPSS

Процентиль: 97%
0.35846
Средний

9.8 Critical

CVSS3

Дефекты

CWE-22