Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j7fp-3pf5-h6cj

Опубликовано: 07 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-306: Missing Authentication for Critical Function, which allows unauthorized users to change the operator account password via webserver commands by monitoring web socket communications from an unauthenticated session. This could allow an attacker to escalate privileges to match those of the compromised account.

The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-306: Missing Authentication for Critical Function, which allows unauthorized users to change the operator account password via webserver commands by monitoring web socket communications from an unauthenticated session. This could allow an attacker to escalate privileges to match those of the compromised account.

EPSS

Процентиль: 48%
0.00245
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-306: Missing Authentication for Critical Function, which allows unauthorized users to change the operator account password via webserver commands by monitoring web socket communications from an unauthenticated session. This could allow an attacker to escalate privileges to match those of the compromised account.

CVSS3: 9.8
fstec
больше 3 лет назад

Уязвимость микропрограммного обеспечения cистемы объемного измерения Cognex 3D-A1000 Dimensioning System, связанная с отсутствием проверки подлинности для функции изменения пароля, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 48%
0.00245
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-306