Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m3cg-wrvh-hrx5

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access via a crafted query, as demonstrated by a V52 query that triggers a power-off action.

hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access via a crafted query, as demonstrated by a V52 query that triggers a power-off action.

EPSS

Процентиль: 98%
0.64232
Средний

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 13 лет назад

hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access via a crafted query, as demonstrated by a V52 query that triggers a power-off action.

EPSS

Процентиль: 98%
0.64232
Средний

Дефекты

CWE-287