Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vp38-x48w-r4cx

Опубликовано: 08 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.8

Описание

The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and unregistered, valid but already registered, or does not exist in the database. Combined with the fact that serial numbers are sequentially assigned, this allows an attacker to gain information on the product registration status of different S/Ns.

The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and unregistered, valid but already registered, or does not exist in the database. Combined with the fact that serial numbers are sequentially assigned, this allows an attacker to gain information on the product registration status of different S/Ns.

EPSS

Процентиль: 22%
0.00297
Низкий

6.9 Medium

CVSS4

5.8 Medium

CVSS3

Дефекты

CWE-203

Связанные уязвимости

CVSS3: 5.8
nvd
12 месяцев назад

The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and unregistered, valid but already registered, or does not exist in the database. Combined with the fact that serial numbers are sequentially assigned, this allows an attacker to gain information on the product registration status of different S/Ns.

EPSS

Процентиль: 22%
0.00297
Низкий

6.9 Medium

CVSS4

5.8 Medium

CVSS3

Дефекты

CWE-203