Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h9fm-vg9q-642c

Опубликовано: 28 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect Access Control. There is a permission bypass vulnerability in the Hillstone WEB application firewall. An attacker can enter the background of the firewall with super administrator privileges through a configuration error in report.m.

https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect Access Control. There is a permission bypass vulnerability in the Hillstone WEB application firewall. An attacker can enter the background of the firewall with super administrator privileges through a configuration error in report.m.

EPSS

Процентиль: 57%
0.00344
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284
CWE-863

Связанные уязвимости

CVSS3: 9.8
nvd
около 3 лет назад

https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect Access Control. There is a permission bypass vulnerability in the Hillstone WEB application firewall. An attacker can enter the background of the firewall with super administrator privileges through a configuration error in report.m.

EPSS

Процентиль: 57%
0.00344
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284
CWE-863