Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qqf5-w389-f489

Опубликовано: 06 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.7

Описание

The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest version which is available on the Eaton download center.

The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest version which is available on the Eaton download center.

EPSS

Процентиль: 8%
0.00029
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 5.7
nvd
6 месяцев назад

The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest version which is available on the Eaton download center.

EPSS

Процентиль: 8%
0.00029
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-295