Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xvv3-3j3q-vgxg

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices. A specially crafted HTTP POST can cause privilege escalation resulting in a higher privileged account, including an undocumented developer level of access.

An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices. A specially crafted HTTP POST can cause privilege escalation resulting in a higher privileged account, including an undocumented developer level of access.

EPSS

Процентиль: 84%
0.02362
Низкий

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 8.8
nvd
около 5 лет назад

An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices. A specially crafted HTTP POST can cause privilege escalation resulting in a higher privileged account, including an undocumented developer level of access.

EPSS

Процентиль: 84%
0.02362
Низкий

Дефекты

CWE-269