Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-whp2-gjjf-pvgr

Опубликовано: 06 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of the device and gain access to its BIOS. Command line options can then be altered, allowing the attacker to access the terminal. From the terminal, the attacker can modify the device’s authentication files to create a new user and gain full access to the system.

An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of the device and gain access to its BIOS. Command line options can then be altered, allowing the attacker to access the terminal. From the terminal, the attacker can modify the device’s authentication files to create a new user and gain full access to the system.

EPSS

Процентиль: 30%
0.00109
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-1263

Связанные уязвимости

CVSS3: 7.6
nvd
почти 3 года назад

An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of the device and gain access to its BIOS. Command line options can then be altered, allowing the attacker to access the terminal. From the terminal, the attacker can modify the device’s authentication files to create a new user and gain full access to the system.

CVSS3: 7.6
fstec
почти 3 года назад

Уязвимость микропрограммного обеспечения вычислительных платформ Moxa серий UC-8100A-ME-T, UC-8200, UC-8410A, UC-2100, UC-2100-W, UC-3100, UC-5100, UC-8100, UC-8580 и UC-8540, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 30%
0.00109
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-1263