Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x6xj-c9qw-4fjp

Опубликовано: 28 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 9.8

Описание

An attacker with access to the network where the vulnerable device is located could capture traffic and obtain cookies from the user, allowing them to steal a user's active session and make changes to the device via the web, depending on the privileges obtained by the user.

An attacker with access to the network where the vulnerable device is located could capture traffic and obtain cookies from the user, allowing them to steal a user's active session and make changes to the device via the web, depending on the privileges obtained by the user.

EPSS

Процентиль: 57%
0.00347
Низкий

6.9 Medium

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
11 месяцев назад

An attacker with network access, could capture traffic and obtain user cookies, allowing the attacker to steal the active user session and make changes to the device via web, depending on the privileges obtained by the user.

EPSS

Процентиль: 57%
0.00347
Низкий

6.9 Medium

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-287