Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wrc6-j5cv-23xc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to remotely retrieve administrative hashed credentials via the maintenance/troubleshoot.php?download=1 URI.

Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to remotely retrieve administrative hashed credentials via the maintenance/troubleshoot.php?download=1 URI.

EPSS

Процентиль: 83%
0.01983
Низкий

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to remotely retrieve administrative hashed credentials via the maintenance/troubleshoot.php?download=1 URI.

EPSS

Процентиль: 83%
0.01983
Низкий

Дефекты

CWE-522