Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j74w-g6f3-9wr9

Опубликовано: 08 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific security patches, is reused in a replay attack against a different system. Even if the target system is fully patched, successful exploitation could result in complete system compromise, affecting confidentiality, integrity, and availability.

An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific security patches, is reused in a replay attack against a different system. Even if the target system is fully patched, successful exploitation could result in complete system compromise, affecting confidentiality, integrity, and availability.

EPSS

Процентиль: 35%
0.00143
Низкий

8.1 High

CVSS3

Дефекты

CWE-308

Связанные уязвимости

CVSS3: 8.1
nvd
7 месяцев назад

An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific security patches, is reused in a replay attack against a different system. Even if the target system is fully patched, successful exploitation could result in complete system compromise, affecting confidentiality, integrity, and availability.

CVSS3: 8.1
fstec
7 месяцев назад

Уязвимость программных интеграционных платформ SAP NetWeaver ABAP Server и ABAP Platform, связанная с применением однофакторной аутентификации, позволяющая нарушителю полностью компрометировать систему

EPSS

Процентиль: 35%
0.00143
Низкий

8.1 High

CVSS3

Дефекты

CWE-308