Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r7mx-84m9-9h4q

Опубликовано: 22 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command ('Command Injection') in Danfoss AK-SM8xxA Series prior to version 4.3.1, leading to a potential post-authenticated remote code execution on an attacked system.

Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command ('Command Injection') in Danfoss AK-SM8xxA Series prior to version 4.3.1, leading to a potential post-authenticated remote code execution on an attacked system.

EPSS

Процентиль: 73%
0.00775
Низкий

8.7 High

CVSS4

Дефекты

CWE-77

Связанные уязвимости

nvd
6 месяцев назад

Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command ('Command Injection') in Danfoss AK-SM8xxA Series prior to version 4.3.1, leading to a potential post-authenticated remote code execution on an attacked system.

EPSS

Процентиль: 73%
0.00775
Низкий

8.7 High

CVSS4

Дефекты

CWE-77