Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hjfh-3qcg-j4x3

Опубликовано: 01 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute arbitrary OS commands as root when the service is reachable over network. Typically, the service is protected via local firewall.

The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute arbitrary OS commands as root when the service is reachable over network. Typically, the service is protected via local firewall.

EPSS

Процентиль: 37%
0.0016
Низкий

8.1 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.1
nvd
2 месяца назад

The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute arbitrary OS commands as root when the service is reachable over network. Typically, the service is protected via local firewall.

EPSS

Процентиль: 37%
0.0016
Низкий

8.1 High

CVSS3

Дефекты

CWE-94