Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hqp8-hfhq-hff8

Опубликовано: 11 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root shell via an unprotected UART port on the device. The same port exposes an unauthenticated Das U-Boot BIOS shell.

Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root shell via an unprotected UART port on the device. The same port exposes an unauthenticated Das U-Boot BIOS shell.

EPSS

Процентиль: 17%
0.00054
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 6.8
nvd
почти 4 года назад

Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root shell via an unprotected UART port on the device. The same port exposes an unauthenticated Das U-Boot BIOS shell.

EPSS

Процентиль: 17%
0.00054
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-798