Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jp8v-m2cx-q392

Опубликовано: 25 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer real CODESYS Gateway password.

In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer real CODESYS Gateway password.

EPSS

Процентиль: 67%
0.0053
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-187

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer real CODESYS Gateway password.

EPSS

Процентиль: 67%
0.0053
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-187