Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vpc6-xqq7-xh2q

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without authentication by triggering use of an invalid SSL certificate and using the Internet Explorer interface to navigate through the filesystem via a "Save As" dialog that is reachable from the "Certificate Export" wizard.

Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without authentication by triggering use of an invalid SSL certificate and using the Internet Explorer interface to navigate through the filesystem via a "Save As" dialog that is reachable from the "Certificate Export" wizard.

EPSS

Процентиль: 56%
0.0034
Низкий

Связанные уязвимости

nvd
около 15 лет назад

Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without authentication by triggering use of an invalid SSL certificate and using the Internet Explorer interface to navigate through the filesystem via a "Save As" dialog that is reachable from the "Certificate Export" wizard.

EPSS

Процентиль: 56%
0.0034
Низкий