Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pvv5-5wph-88cq

Опубликовано: 11 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.7

Описание

TP-Link L2 switch T2600G-28SQ firmware versions prior to 'T2600G-28SQ(UN)_V1_1.0.6 Build 20230227' uses vulnerable SSH host keys. A fake device may be prepared to spoof the affected device with the vulnerable host key.If the administrator may be tricked to login to the fake device, the credential information for the affected device may be obtained.

TP-Link L2 switch T2600G-28SQ firmware versions prior to 'T2600G-28SQ(UN)_V1_1.0.6 Build 20230227' uses vulnerable SSH host keys. A fake device may be prepared to spoof the affected device with the vulnerable host key.If the administrator may be tricked to login to the fake device, the credential information for the affected device may be obtained.

EPSS

Процентиль: 15%
0.00049
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-1391

Связанные уязвимости

CVSS3: 5.7
nvd
почти 3 года назад

TP-Link L2 switch T2600G-28SQ firmware versions prior to 'T2600G-28SQ(UN)_V1_1.0.6 Build 20230227' uses vulnerable SSH host keys. A fake device may be prepared to spoof the affected device with the vulnerable host key.If the administrator may be tricked to login to the fake device, the credential information for the affected device may be obtained.

CVSS3: 5.7
fstec
почти 3 года назад

Уязвимость микропрограммного обеспечения коммутаторов TP-Link T2600G-28SQ, связанная с ошибками управления регистрационными данными, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 15%
0.00049
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-1391