Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wj48-f7rr-8fm2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The length of the input fields of Host Engineering H0-ECOM100, H2-ECOM100, and H4-ECOM100 modules are verified only on the client side when receiving input from the configuration web server, which may allow an attacker to bypass the check and send input to crash the device.

The length of the input fields of Host Engineering H0-ECOM100, H2-ECOM100, and H4-ECOM100 modules are verified only on the client side when receiving input from the configuration web server, which may allow an attacker to bypass the check and send input to crash the device.

EPSS

Процентиль: 45%
0.00229
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
nvd
около 5 лет назад

The length of the input fields of Host Engineering H0-ECOM100, H2-ECOM100, and H4-ECOM100 modules are verified only on the client side when receiving input from the configuration web server, which may allow an attacker to bypass the check and send input to crash the device.

EPSS

Процентиль: 45%
0.00229
Низкий

Дефекты

CWE-20