Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m84g-fpm8-mqg8

Опубликовано: 24 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded value accessible via the web interface. Because Base64 is reversible and provides no confidentiality, an attacker who can access the cookie value can recover the plaintext password.

Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded value accessible via the web interface. Because Base64 is reversible and provides no confidentiality, an attacker who can access the cookie value can recover the plaintext password.

EPSS

Процентиль: 5%
0.00019
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 7.5
nvd
3 месяца назад

Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded value accessible via the web interface. Because Base64 is reversible and provides no confidentiality, an attacker who can access the cookie value can recover the plaintext password.

EPSS

Процентиль: 5%
0.00019
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-312