Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xvgp-q85q-wcrm

Опубликовано: 13 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially crafted strings. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI command. The vulnerability allows the attack

A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially crafted strings. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI command. The vulnerability allows the attack

EPSS

Процентиль: 40%
0.00181
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 6.4
nvd
почти 3 года назад

A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially crafted strings. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI command. The vulnerability allows the attack

EPSS

Процентиль: 40%
0.00181
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-77