Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rh9w-mh4f-p3x9

Опубликовано: 14 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5

Описание

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions for specific write queries. This could allow an authenticated remote attacker to perform unauthorized actions.

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions for specific write queries. This could allow an authenticated remote attacker to perform unauthorized actions.

EPSS

Процентиль: 52%
0.00289
Низкий

5 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5
nvd
почти 3 года назад

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions for specific write queries. This could allow an authenticated remote attacker to perform unauthorized actions.

CVSS3: 8.8
fstec
почти 3 года назад

Уязвимость обработчика клиентских запросов системы безопасного управления доступом к IED Siemens RUGGEDCOM CROSSBOW, позволяющая нарушителю выполнить произвольные действия

EPSS

Процентиль: 52%
0.00289
Низкий

5 Medium

CVSS3

Дефекты

CWE-862