Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qqqv-wfvc-wrgw

Опубликовано: 14 янв. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on the My Cloud devices. Addressed this vulnerability by changing access token validation logic and rewriting rule logic on PHP scripts.

A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on the My Cloud devices. Addressed this vulnerability by changing access token validation logic and rewriting rule logic on PHP scripts.

EPSS

Процентиль: 82%
0.0171
Низкий

8.8 High

CVSS3

Дефекты

CWE-287
CWE-697

Связанные уязвимости

CVSS3: 7.8
nvd
около 4 лет назад

A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on the My Cloud devices. Addressed this vulnerability by changing access token validation logic and rewriting rule logic on PHP scripts.

EPSS

Процентиль: 82%
0.0171
Низкий

8.8 High

CVSS3

Дефекты

CWE-287
CWE-697