Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x58f-9h5m-89hm

Опубликовано: 22 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator. Note that this attack could be successful only if the administrator has not logged out.

The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator. Note that this attack could be successful only if the administrator has not logged out.

EPSS

Процентиль: 21%
0.00066
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 5.5
nvd
больше 1 года назад

The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator. Note that this attack could be successful only if the administrator has not logged out.

EPSS

Процентиль: 21%
0.00066
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-522