Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m57f-9997-gm6m

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.1

Описание

A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choosing. The vulnerability is due to uncontrolled search path elements. An attacker could exploit this vulnerability by placing a binary of their choosing earlier in the search path utilized by Cisco Directory Connector to locate and load required resources.

A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choosing. The vulnerability is due to uncontrolled search path elements. An attacker could exploit this vulnerability by placing a binary of their choosing earlier in the search path utilized by Cisco Directory Connector to locate and load required resources.

EPSS

Процентиль: 20%
0.00066
Низкий

5.1 Medium

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 5.1
nvd
почти 7 лет назад

A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choosing. The vulnerability is due to uncontrolled search path elements. An attacker could exploit this vulnerability by placing a binary of their choosing earlier in the search path utilized by Cisco Directory Connector to locate and load required resources.

CVSS3: 5.1
fstec
почти 7 лет назад

Уязвимость приложения для синхронизации идентификаторов в облаке Cisco Directory Connector, связанная с ошибками механизма проверки пути поиска, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 20%
0.00066
Низкий

5.1 Medium

CVSS3

Дефекты

CWE-427