Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vg8h-77qg-7w2f

Опубликовано: 13 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

The Akuvox E11 password recovery webpage can be accessed without authentication, and an attacker could download the device key file. An attacker could then use this page to reset the password back to the default.

The Akuvox E11 password recovery webpage can be accessed without authentication, and an attacker could download the device key file. An attacker could then use this page to reset the password back to the default.

EPSS

Процентиль: 31%
0.00115
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 9.1
nvd
почти 3 года назад

The Akuvox E11 password recovery webpage can be accessed without authentication, and an attacker could download the device key file. An attacker could then use this page to reset the password back to the default.

EPSS

Процентиль: 31%
0.00115
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-640