Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rcv8-v727-xg26

Опубликовано: 22 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it. A vulnerability exists in which an attacker could impersonate a hub and send device requests to claim already claimed devices. The OvrC cloud platform receives the requests but does not validate if the found devices are already managed by another user.

The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it. A vulnerability exists in which an attacker could impersonate a hub and send device requests to claim already claimed devices. The OvrC cloud platform receives the requests but does not validate if the found devices are already managed by another user.

EPSS

Процентиль: 15%
0.00049
Низкий

8.6 High

CVSS3

Дефекты

CWE-20
CWE-413

Связанные уязвимости

CVSS3: 8.6
nvd
больше 2 лет назад

The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it. A vulnerability exists in which an attacker could impersonate a hub and send device requests to claim already claimed devices. The OvrC cloud platform receives the requests but does not validate if the found devices are already managed by another user.

EPSS

Процентиль: 15%
0.00049
Низкий

8.6 High

CVSS3

Дефекты

CWE-20
CWE-413