Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v5vf-cpv3-c3fj

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.7

Описание

A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access the Graphite web interface. The attacker would need to have access to the internal VLAN where CPS is deployed. The vulnerability is due to lack of authentication. An attacker could exploit this vulnerability by directly connecting to the Graphite web interface. An exploit could allow the attacker to access various statistics and Key Performance Indicators (KPIs) regarding the Cisco Policy Suite environment.

A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access the Graphite web interface. The attacker would need to have access to the internal VLAN where CPS is deployed. The vulnerability is due to lack of authentication. An attacker could exploit this vulnerability by directly connecting to the Graphite web interface. An exploit could allow the attacker to access various statistics and Key Performance Indicators (KPIs) regarding the Cisco Policy Suite environment.

EPSS

Процентиль: 69%
0.00605
Низкий

3.7 Low

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 5.3
nvd
около 7 лет назад

A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access the Graphite web interface. The attacker would need to have access to the internal VLAN where CPS is deployed. The vulnerability is due to lack of authentication. An attacker could exploit this vulnerability by directly connecting to the Graphite web interface. An exploit could allow the attacker to access various statistics and Key Performance Indicators (KPIs) regarding the Cisco Policy Suite environment.

CVSS3: 3.7
fstec
около 7 лет назад

Уязвимость веб-интерфейса Graphite программного обеспечения для управления политиками, начисления платы и управления абонентскими данными Cisco Policy Suite for Mobile, позволяющая нарушителю получить доступ к защищаемым данным

EPSS

Процентиль: 69%
0.00605
Низкий

3.7 Low

CVSS3

Дефекты

CWE-306