Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q8rg-c9v7-62r5

Опубликовано: 26 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM privileges on all connected nodes in NAC through this vulnerability.

An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM privileges on all connected nodes in NAC through this vulnerability.

EPSS

Процентиль: 84%
0.02273
Низкий

10 Critical

CVSS3

Дефекты

CWE-20
CWE-94

Связанные уязвимости

CVSS3: 9.6
nvd
почти 4 года назад

An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM privileges on all connected nodes in NAC through this vulnerability.

EPSS

Процентиль: 84%
0.02273
Низкий

10 Critical

CVSS3

Дефекты

CWE-20
CWE-94