Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rggx-gpg5-f3h9

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS service. An attacker who can connect to the DSS service on the Trane ComfortLink II device can send an overly long REG request that can overflow a fixed size stack buffer, resulting in arbitrary code execution.

An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS service. An attacker who can connect to the DSS service on the Trane ComfortLink II device can send an overly long REG request that can overflow a fixed size stack buffer, resulting in arbitrary code execution.

EPSS

Процентиль: 92%
0.09063
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 9.8
nvd
около 9 лет назад

An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS service. An attacker who can connect to the DSS service on the Trane ComfortLink II device can send an overly long REG request that can overflow a fixed size stack buffer, resulting in arbitrary code execution.

CVSS3: 9.8
fstec
почти 12 лет назад

Уязвимость службы DSS микропрограммного обеспечения термостата ComfortLink II, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 92%
0.09063
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-119