Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wrwf-2jpv-j2gv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a use-after-free condition which could result in remote code execution when a malicious SSD file is uploaded and improperly parsed.

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a use-after-free condition which could result in remote code execution when a malicious SSD file is uploaded and improperly parsed.

EPSS

Процентиль: 72%
0.0071
Низкий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.8
nvd
около 5 лет назад

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a use-after-free condition which could result in remote code execution when a malicious SSD file is uploaded and improperly parsed.

CVSS3: 7.8
fstec
около 5 лет назад

Уязвимость программного обеспечения онлайн-конфигурации EcoStruxure Power Build, связанная с неограниченной загрузкой файлов опасного типа, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 72%
0.0071
Низкий

Дефекты

CWE-434