Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rgfw-9xmc-3h72

Опубликовано: 02 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 8.8

Описание

A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and send requests to claim and unclaim devices. The attacker only needs to provide the MAC address of the targeted device and can make a request to unclaim it from its original connection and make a request to claim it.

A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and send requests to claim and unclaim devices. The attacker only needs to provide the MAC address of the targeted device and can make a request to unclaim it from its original connection and make a request to claim it.

EPSS

Процентиль: 44%
0.00217
Низкий

8.8 High

CVSS4

Дефекты

CWE-306

Связанные уязвимости

nvd
около 1 года назад

A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and send requests to claim and unclaim devices. The attacker only needs to provide the MAC address of the targeted device and can make a request to unclaim it from its original connection and make a request to claim it.

CVSS3: 9.1
fstec
около 1 года назад

Уязвимость команды dsUnclaimHubоблачной платформы управления ИТ-инфраструктурой OvrC Pro, позволяющая нарушителю получить несанкционированный доступ на добавление или удаление сетевых устройств

EPSS

Процентиль: 44%
0.00217
Низкий

8.8 High

CVSS4

Дефекты

CWE-306