Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qxgr-6j8v-x3cr

Опубликовано: 15 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges to upload arbitrary files. By uploading a specially crafted tar file an attacker can execute arbitrary commands.

A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges to upload arbitrary files. By uploading a specially crafted tar file an attacker can execute arbitrary commands.

EPSS

Процентиль: 62%
0.0043
Низкий

8.8 High

CVSS3

Дефекты

CWE-22
CWE-23

Связанные уязвимости

CVSS3: 7.6
nvd
почти 4 года назад

A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges to upload arbitrary files. By uploading a specially crafted tar file an attacker can execute arbitrary commands.

EPSS

Процентиль: 62%
0.0043
Низкий

8.8 High

CVSS3

Дефекты

CWE-22
CWE-23