Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q8j4-3fxm-87xm

Опубликовано: 06 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

All versions of Econolite EOS traffic control software are vulnerable to CWE-284: Improper Access Control, and lack a password requirement for gaining “READONLY” access to log files, as well as certain database and configuration files. One such file contains tables with message-digest algorithm 5 (MD5) hashes and usernames for all defined users in the control software, including administrators and technicians.

All versions of Econolite EOS traffic control software are vulnerable to CWE-284: Improper Access Control, and lack a password requirement for gaining “READONLY” access to log files, as well as certain database and configuration files. One such file contains tables with message-digest algorithm 5 (MD5) hashes and usernames for all defined users in the control software, including administrators and technicians.

EPSS

Процентиль: 38%
0.00164
Низкий

7.5 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.5
nvd
около 3 лет назад

Econolite EOS versions prior to 3.2.23 lack a password requirement for gaining “READONLY” access to log files and certain database and configuration files. One such file contains tables with MD5 hashes and usernames for all defined users in the control software, including administrators and technicians.

EPSS

Процентиль: 38%
0.00164
Низкий

7.5 High

CVSS3

Дефекты

CWE-284