Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v2r7-frxx-fmq5

Опубликовано: 07 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated access to run code of the attacker's choosing.

Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated access to run code of the attacker's choosing.

EPSS

Процентиль: 99%
0.88732
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-285
CWE-306

Связанные уязвимости

CVSS3: 9.8
nvd
около 3 лет назад

Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated access to run code of the attacker's choosing.

CVSS3: 9.8
fstec
больше 3 лет назад

Уязвимость веб-интерфейса управления программного средства удаленного управления компьютером Unified Remote, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 99%
0.88732
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-285
CWE-306