Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mp76-mqjp-pxx7

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A vulnerability in the Enhanced Charging Service (ECS) functionality of Cisco ASR 5000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass the traffic classification rules on an affected device. The vulnerability is due to insufficient input validation of user traffic going through an affected device. An attacker could exploit this vulnerability by sending a malformed HTTP request to an affected device. A successful exploit could allow the attacker to bypass the traffic classification rules and potentially avoid being charged for traffic consumption.

A vulnerability in the Enhanced Charging Service (ECS) functionality of Cisco ASR 5000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass the traffic classification rules on an affected device. The vulnerability is due to insufficient input validation of user traffic going through an affected device. An attacker could exploit this vulnerability by sending a malformed HTTP request to an affected device. A successful exploit could allow the attacker to bypass the traffic classification rules and potentially avoid being charged for traffic consumption.

EPSS

Процентиль: 61%
0.00418
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.3
nvd
больше 5 лет назад

A vulnerability in the Enhanced Charging Service (ECS) functionality of Cisco ASR 5000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass the traffic classification rules on an affected device. The vulnerability is due to insufficient input validation of user traffic going through an affected device. An attacker could exploit this vulnerability by sending a malformed HTTP request to an affected device. A successful exploit could allow the attacker to bypass the traffic classification rules and potentially avoid being charged for traffic consumption.

CVSS3: 5.3
fstec
больше 5 лет назад

Уязвимость службы Enhanced Charging Service микропрограммного обеспечения маршрутизатора Cisco ASR 5000, позволяющая нарушителю обойти правила классификации трафика и потенциально избежать оплаты за потребление трафика

CVSS3: 5.3
fstec
больше 5 лет назад

Уязвимость системы автоматизации деятельности предприятия IBM Business Process Manager и программного средства автоматизации цифровых процессов IBM Business Automation Workflow, связанная с ошибками разграничения доступа, позволяющая нарушителю получить доступ к защищаемой информации

EPSS

Процентиль: 61%
0.00418
Низкий

Дефекты

CWE-20