Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vgvm-wwrq-c4xw

Опубликовано: 06 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS

Процентиль: 34%
0.00137
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-269
CWE-434
CWE-863

Связанные уязвимости

CVSS3: 5.4
nvd
почти 3 года назад

An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS

Процентиль: 34%
0.00137
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-269
CWE-434
CWE-863