Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p8qm-v86v-r6gq

Опубликовано: 24 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 7.5

Описание

FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands without authentication.

FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands without authentication.

EPSS

Процентиль: 50%
0.00267
Низкий

9.3 Critical

CVSS4

7.5 High

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 месяцев назад

FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands without authentication.

EPSS

Процентиль: 50%
0.00267
Низкий

9.3 Critical

CVSS4

7.5 High

CVSS3

Дефекты

CWE-798