Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j4rf-24v6-vq7x

Опубликовано: 16 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenticated, local attacker with low privileges to view passwords on an affected device.

This vulnerability is due to incorrect sanitization of HTML content from an affected device. A successful exploit could allow the attacker to view passwords that belong to other users.

A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenticated, local attacker with low privileges to view passwords on an affected device.

This vulnerability is due to incorrect sanitization of HTML content from an affected device. A successful exploit could allow the attacker to view passwords that belong to other users.

EPSS

Процентиль: 26%
0.00091
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-257
CWE-522
CWE-922

Связанные уязвимости

CVSS3: 5.5
nvd
больше 1 года назад

A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenticated, local attacker with low privileges to view passwords on an affected device. This vulnerability is due to incorrect sanitization of HTML content from an affected device. A successful exploit could allow the attacker to view passwords that belong to other users.

CVSS3: 5.5
fstec
больше 1 года назад

Уязвимость веб-интерфейса управления микропрограммного обеспечения устройств IP-телефонии Cisco Analog Telephone Adapter (ATA) серии 190, позволяющая нарушителю просматривать пароли произвольных пользователей

EPSS

Процентиль: 26%
0.00091
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-257
CWE-522
CWE-922