Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rfvx-872w-6rpr

Опубликовано: 15 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.3

Описание

The ventilator does not perform proper file integrity checks when adopting firmware updates. This makes it possible for an attacker to force unauthorized changes to the device's configuration settings and/or compromise device functionality by pushing a compromised/illegitimate firmware file. This could disrupt the function of the device and/or cause unauthorized information disclosure.

The ventilator does not perform proper file integrity checks when adopting firmware updates. This makes it possible for an attacker to force unauthorized changes to the device's configuration settings and/or compromise device functionality by pushing a compromised/illegitimate firmware file. This could disrupt the function of the device and/or cause unauthorized information disclosure.

EPSS

Процентиль: 18%
0.00056
Низкий

9.3 Critical

CVSS3

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 9.3
nvd
около 1 года назад

The ventilator does not perform proper file integrity checks when adopting firmware updates. This makes it possible for an attacker to force unauthorized changes to the device's configuration settings and/or compromise device functionality by pushing a compromised/illegitimate firmware file. This could disrupt the function of the device and/or cause unauthorized information disclosure.

EPSS

Процентиль: 18%
0.00056
Низкий

9.3 Critical

CVSS3

Дефекты

CWE-494