Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r7vh-7qjc-wcjc

Опубликовано: 12 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 2.7

Описание

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The REST API of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server by sending a crafted request to the API. The server will automatically restart.

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The REST API of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server by sending a crafted request to the API. The server will automatically restart.

EPSS

Процентиль: 28%
0.00102
Низкий

2.7 Low

CVSS3

Дефекты

CWE-392

Связанные уязвимости

CVSS3: 2.7
nvd
около 2 лет назад

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The REST API of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server by sending a crafted request to the API. The server will automatically restart.

EPSS

Процентиль: 28%
0.00102
Низкий

2.7 Low

CVSS3

Дефекты

CWE-392