Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rjxr-qvqf-h58w

Опубликовано: 23 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.4

Описание

There is an OS command injection vulnerability in Crestron AM-300 firmware version 1.4499.00018 which may enable a user of a limited-access SSH session to escalate their privileges to root-level access.

There is an OS command injection vulnerability in Crestron AM-300 firmware version 1.4499.00018 which may enable a user of a limited-access SSH session to escalate their privileges to root-level access.

EPSS

Процентиль: 40%
0.00182
Низкий

8.4 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.4
nvd
около 2 лет назад

There is an OS command injection vulnerability in Crestron AM-300 firmware version 1.4499.00018 which may enable a user of a limited-access SSH session to escalate their privileges to root-level access.

EPSS

Процентиль: 40%
0.00182
Низкий

8.4 High

CVSS3

Дефекты

CWE-78