Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mv7w-j26m-h74p

Опубликовано: 02 мая 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 10

Описание

KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote attacker full access to the Node-RED server where they can run arbitrary commands on the underlying operating system.

KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote attacker full access to the Node-RED server where they can run arbitrary commands on the underlying operating system.

EPSS

Процентиль: 36%
0.00155
Низкий

9.3 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-305

Связанные уязвимости

CVSS3: 10
nvd
9 месяцев назад

KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote attacker full access to the Node-RED server where they can run arbitrary commands on the underlying operating system.

EPSS

Процентиль: 36%
0.00155
Низкий

9.3 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-305