Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h9xp-3922-7v5q

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 handles system parameters in an insecure way. An authenticated SD-WAN Orchestrator user with high privileges may be able to execute arbitrary code on the underlying operating system.

The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 handles system parameters in an insecure way. An authenticated SD-WAN Orchestrator user with high privileges may be able to execute arbitrary code on the underlying operating system.

EPSS

Процентиль: 68%
0.00566
Низкий

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.2
nvd
около 5 лет назад

The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 handles system parameters in an insecure way. An authenticated SD-WAN Orchestrator user with high privileges may be able to execute arbitrary code on the underlying operating system.

EPSS

Процентиль: 68%
0.00566
Низкий

Дефекты

CWE-732