Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xg8h-h4cf-qvvx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarded-For header with the local (loopback) IP address value allowing remote control of the smart home solution.

HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarded-For header with the local (loopback) IP address value allowing remote control of the smart home solution.

EPSS

Процентиль: 83%
0.01868
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-290

Связанные уязвимости

CVSS3: 9.8
nvd
почти 5 лет назад

HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarded-For header with the local (loopback) IP address value allowing remote control of the smart home solution.

EPSS

Процентиль: 83%
0.01868
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-290