Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xxpf-83g5-3w2v

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, which allows remote attackers to obtain sensitive information, delete files, execute arbitrary programs, or cause a denial of service (crash) via a crafted packet to TCP port 10651.

TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, which allows remote attackers to obtain sensitive information, delete files, execute arbitrary programs, or cause a denial of service (crash) via a crafted packet to TCP port 10651.

EPSS

Процентиль: 93%
0.0993
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
около 14 лет назад

TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, which allows remote attackers to obtain sensitive information, delete files, execute arbitrary programs, or cause a denial of service (crash) via a crafted packet to TCP port 10651.

EPSS

Процентиль: 93%
0.0993
Низкий

Дефекты

CWE-287