Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w6r8-h9q4-qq7v

Опубликовано: 20 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 1
CVSS3: 2.3

Описание

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized access to sensitive credential data when an attacker is able to capture local SMB traffic between a valid user within the BMS network and the vulnerable products.

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized access to sensitive credential data when an attacker is able to capture local SMB traffic between a valid user within the BMS network and the vulnerable products.

EPSS

Процентиль: 5%
0.00022
Низкий

1 Low

CVSS4

2.3 Low

CVSS3

Дефекты

CWE-200

Связанные уязвимости

nvd
6 месяцев назад

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized access to sensitive credential data when an attacker is able to capture local SMB traffic between a valid user within the BMS network and the vulnerable products.

CVSS3: 2.3
fstec
6 месяцев назад

Уязвимость серверов EcoStruxure Building Operation Enterprise Central, EcoStruxure Building Operation Enterprise Server и интерфейса рабочей станции EcoStruxure Workstation, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 5%
0.00022
Низкий

1 Low

CVSS4

2.3 Low

CVSS3

Дефекты

CWE-200