Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p3j9-952w-4qf7

Опубликовано: 10 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to obtain remote code execution (RCE) with root privileges on the device.

The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to obtain remote code execution (RCE) with root privileges on the device.

EPSS

Процентиль: 84%
0.02069
Низкий

8.1 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.1
nvd
около 2 лет назад

The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to obtain remote code execution (RCE) with root privileges on the device.

CVSS3: 8.8
fstec
около 2 лет назад

Уязвимость операционной системы NEXO-OS инструментов для монтажных работ на производственных линиях Bosch Nexo cordless nutrunner и Bosch Nexo special cordless nutrunner, позволяющая нарушителю загрузить произвольные файлы и выполнить произвольный код

EPSS

Процентиль: 84%
0.02069
Низкий

8.1 High

CVSS3

Дефекты

CWE-22