Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jw2m-w7c2-h66c

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a crafted configuration file to the managing server, which may result in the managed clients to execute arbitrary code with the administrative privilege.

Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a crafted configuration file to the managing server, which may result in the managed clients to execute arbitrary code with the administrative privilege.

EPSS

Процентиль: 91%
0.07008
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a crafted configuration file to the managing server, which may result in the managed clients to execute arbitrary code with the administrative privilege.

EPSS

Процентиль: 91%
0.07008
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-306