Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rwmc-xpj5-264g

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow a remote attacker to delete arbitrary system file due to lack of validation of the /login/bin/set_param to the file name with the value of 'system.delete.sd_file'

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow a remote attacker to delete arbitrary system file due to lack of validation of the /login/bin/set_param to the file name with the value of 'system.delete.sd_file'

EPSS

Процентиль: 67%
0.00527
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.1
nvd
почти 8 лет назад

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow a remote attacker to delete arbitrary system file due to lack of validation of the /login/bin/set_param to the file name with the value of 'system.delete.sd_file'

EPSS

Процентиль: 67%
0.00527
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-20