Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-whp9-r49x-695c

Опубликовано: 01 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

LOYTEC electronics GmbH LINX Configurator 7.4.10 is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so it allows remote attackers to steal the password and gain full control of Loytec device configuration.

LOYTEC electronics GmbH LINX Configurator 7.4.10 is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so it allows remote attackers to steal the password and gain full control of Loytec device configuration.

EPSS

Процентиль: 34%
0.00135
Низкий

7.5 High

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 лет назад

LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so it allows remote attackers to steal the password and gain full control of Loytec device configuration.

EPSS

Процентиль: 34%
0.00135
Низкий

7.5 High

CVSS3

Дефекты

CWE-319