Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v334-55hv-wvc6

Опубликовано: 30 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 all serial numbers allows a remote unauthenticated attacker to bypass authentication by capture-replay attack and illegally login to the affected module. As a result, the remote attacker who has logged in illegally may be able to disclose or tamper with the programs and parameters in the modules.

Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 all serial numbers allows a remote unauthenticated attacker to bypass authentication by capture-replay attack and illegally login to the affected module. As a result, the remote attacker who has logged in illegally may be able to disclose or tamper with the programs and parameters in the modules.

EPSS

Процентиль: 75%
0.00887
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-294

Связанные уязвимости

CVSS3: 5.9
nvd
около 2 лет назад

Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 all serial numbers allows a remote unauthenticated attacker to bypass authentication by capture-replay attack and illegally login to the affected module. As a result, the remote attacker who has logged in illegally may be able to disclose or tamper with the programs and parameters in the modules.

CVSS3: 5.9
fstec
около 2 лет назад

Уязвимость микропрограммного обеспечения программируемых логических контроллеров MELSEC WS0-GETH00200, связанная с обходом процедуры аутентификации, позволяющая нарушителю обойти процесс аутентификации

EPSS

Процентиль: 75%
0.00887
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-294