Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w93w-26gf-h3c5

Опубликовано: 05 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, an attacker can connect to the PLC and read the project without authorization.

All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, an attacker can connect to the PLC and read the project without authorization.

EPSS

Процентиль: 52%
0.00285
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, an attacker can connect to the PLC and read the project without authorization.

EPSS

Процентиль: 52%
0.00285
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287