Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jg72-rmmw-hp49

Опубликовано: 29 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The Grandstream UCM Series IP PBX before firmware version 1.0.20.52 is affected by a parameter injection vulnerability in the HTTP interface. A remote and authenticated attacker can execute arbitrary code by sending a crafted HTTP request. Authentication may be possible using a default user and password. Affected models are the UCM6202, UCM6204, UCM6208, and UCM6510.

The Grandstream UCM Series IP PBX before firmware version 1.0.20.52 is affected by a parameter injection vulnerability in the HTTP interface. A remote and authenticated attacker can execute arbitrary code by sending a crafted HTTP request. Authentication may be possible using a default user and password. Affected models are the UCM6202, UCM6204, UCM6208, and UCM6510.

EPSS

Процентиль: 59%
0.00374
Низкий

8.8 High

CVSS3

Дефекты

CWE-141

Связанные уязвимости

CVSS3: 8.8
nvd
почти 2 года назад

The Grandstream UCM Series IP PBX before firmware version 1.0.20.52 is affected by a parameter injection vulnerability in the HTTP interface. A remote and authenticated attacker can execute arbitrary code by sending a crafted HTTP request. Authentication may be possible using a default user and password. Affected models are the UCM6202, UCM6204, UCM6208, and UCM6510.

EPSS

Процентиль: 59%
0.00374
Низкий

8.8 High

CVSS3

Дефекты

CWE-141