Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j9fc-qr37-r7w7

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, and then capturing the credentials that are sent there. This occurs because stored credentials are not automatically deleted upon that type of hostname change.

On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, and then capturing the credentials that are sent there. This occurs because stored credentials are not automatically deleted upon that type of hostname change.

EPSS

Процентиль: 51%
0.00281
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.9
nvd
почти 7 лет назад

On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, and then capturing the credentials that are sent there. This occurs because stored credentials are not automatically deleted upon that type of hostname change.

EPSS

Процентиль: 51%
0.00281
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-200