Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wrcw-xwfj-3r9j

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

A vulnerability in Cisco AMP Threat Grid could allow an authenticated, remote attacker to access sensitive information. The vulnerability is due to unsafe creation of API keys. An attacker could exploit this vulnerability by using insecure credentials to gain unauthorized access to the affected device. An exploit could allow the attacker to gain unauthorized access to information by using the API key credentials.

A vulnerability in Cisco AMP Threat Grid could allow an authenticated, remote attacker to access sensitive information. The vulnerability is due to unsafe creation of API keys. An attacker could exploit this vulnerability by using insecure credentials to gain unauthorized access to the affected device. An exploit could allow the attacker to gain unauthorized access to information by using the API key credentials.

EPSS

Процентиль: 39%
0.00173
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
около 7 лет назад

A vulnerability in Cisco AMP Threat Grid could allow an authenticated, remote attacker to access sensitive information. The vulnerability is due to unsafe creation of API keys. An attacker could exploit this vulnerability by using insecure credentials to gain unauthorized access to the affected device. An exploit could allow the attacker to gain unauthorized access to information by using the API key credentials.

CVSS3: 4.3
fstec
около 7 лет назад

Уязвимость платформы обнаружения вредоносного кода Cisco AMP Threat Grid, связанная с небезопасным созданием ключей API, позволяющая нарушителю получить доступ к защищаемой информации

EPSS

Процентиль: 39%
0.00173
Низкий

4.3 Medium

CVSS3