Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wwvm-vmw2-56q8

Опубликовано: 12 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7
CVSS3: 3.7

Описание

When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the UPS server configuation.

This issue affects ADM: from 4.1.0 through 4.3.3.RKD2, from 5.0.0 through 5.1.0.RN42.

When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the UPS server configuation.

This issue affects ADM: from 4.1.0 through 4.3.3.RKD2, from 5.0.0 through 5.1.0.RN42.

EPSS

Процентиль: 1%
0.0001
Низкий

7 High

CVSS4

3.7 Low

CVSS3

Дефекты

CWE-311

Связанные уязвимости

CVSS3: 3.7
nvd
около 2 месяцев назад

When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the UPS server configuation. This issue affects ADM: from 4.1.0 through 4.3.3.RKD2, from 5.0.0 through 5.1.0.RN42.

EPSS

Процентиль: 1%
0.0001
Низкий

7 High

CVSS4

3.7 Low

CVSS3

Дефекты

CWE-311