Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vfgc-wr54-m4r5

Опубликовано: 14 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

This vulnerability potentially allows unauthorized enumeration of information from the embedded device APIs. An attacker must already have existing knowledge of some combination of valid usernames, device names and an internal system key. For such an attack to be successful the system must be in a specific runtime state.

This vulnerability potentially allows unauthorized enumeration of information from the embedded device APIs. An attacker must already have existing knowledge of some combination of valid usernames, device names and an internal system key. For such an attack to be successful the system must be in a specific runtime state.

EPSS

Процентиль: 66%
0.00512
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-200
CWE-488

Связанные уязвимости

CVSS3: 4.8
nvd
почти 2 года назад

This vulnerability potentially allows unauthorized enumeration of information from the embedded device APIs. An attacker must already have existing knowledge of some combination of valid usernames, device names and an internal system key. For such an attack to be successful the system must be in a specific runtime state.

EPSS

Процентиль: 66%
0.00512
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-200
CWE-488