Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m4cp-qj9v-7wpc

Опубликовано: 15 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6

Описание

Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script calls to system.sh from within the SNMP binary. An authenticated attacker could perform command or parameter injection on SNMP operations that are only enabled on the Brocade 6547 (FC5022) embedded switch. This injection could allow the authenticated attacker to issue commands as Root.

Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script calls to system.sh from within the SNMP binary. An authenticated attacker could perform command or parameter injection on SNMP operations that are only enabled on the Brocade 6547 (FC5022) embedded switch. This injection could allow the authenticated attacker to issue commands as Root.

EPSS

Процентиль: 52%
0.00285
Низкий

8.6 High

CVSS4

Дефекты

CWE-77
CWE-78

Связанные уязвимости

nvd
12 месяцев назад

Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script calls to system.sh from within the SNMP binary. An authenticated attacker could perform command or parameter injection on SNMP operations that are only enabled on the Brocade 6547 (FC5022) embedded switch. This injection could allow the authenticated attacker to issue commands as Root.

EPSS

Процентиль: 52%
0.00285
Низкий

8.6 High

CVSS4

Дефекты

CWE-77
CWE-78