Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hgf8-22gv-6hjf

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have direct unauthorized access to other vSmart containers. The vulnerability is due to an insecure default configuration of the affected system. An attacker could exploit this vulnerability by directly connecting to the exposed services. An exploit could allow the attacker to retrieve and modify critical system files.

A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have direct unauthorized access to other vSmart containers. The vulnerability is due to an insecure default configuration of the affected system. An attacker could exploit this vulnerability by directly connecting to the exposed services. An exploit could allow the attacker to retrieve and modify critical system files.

EPSS

Процентиль: 74%
0.00853
Низкий

8 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 8
nvd
около 7 лет назад

A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have direct unauthorized access to other vSmart containers. The vulnerability is due to an insecure default configuration of the affected system. An attacker could exploit this vulnerability by directly connecting to the exposed services. An exploit could allow the attacker to retrieve and modify critical system files.

CVSS3: 8
fstec
около 7 лет назад

Уязвимость программно-определяемой сети Cisco SD-WAN, связанная с недостатками контроля доступа, позволяющая нарушителю обойти процедуру аутентификации и получить доступ к системным файлам

EPSS

Процентиль: 74%
0.00853
Низкий

8 High

CVSS3

Дефекты

CWE-284