Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wg23-cr77-5r75

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges.

A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges.

EPSS

Процентиль: 94%
0.14944
Средний

8.8 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.8
nvd
больше 5 лет назад

A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges.

suse-cvrf
больше 5 лет назад

Security update for nextcloud

EPSS

Процентиль: 94%
0.14944
Средний

8.8 High

CVSS3

Дефекты

CWE-78