Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-px84-m7h4-295j

Опубликовано: 18 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 6.5

Описание

HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access role through XML-based NETCONF configuration. Attackers can send crafted XML payloads to the /mops_data endpoint with a specific role value to elevate their user privileges to administrative level.

HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access role through XML-based NETCONF configuration. Attackers can send crafted XML payloads to the /mops_data endpoint with a specific role value to elevate their user privileges to administrative level.

EPSS

Процентиль: 0%
0.00006
Низкий

8.7 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 месяцев назад

HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access role through XML-based NETCONF configuration. Attackers can send crafted XML payloads to the /mops_data endpoint with a specific role value to elevate their user privileges to administrative level.

EPSS

Процентиль: 0%
0.00006
Низкий

8.7 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-269