Описание
The processor_request function in the debugger server for DataRescue IDA Pro 5.0 and 5.1 does not verify that authentication has taken place before invoking the perform_request function, which allows remote attackers to perform unauthorized actions.
Ссылки
- Vendor Advisory
- Patch
- Vendor Advisory
- Vendor Advisory
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:datarescue:ida_pro:5.0:*:*:*:*:*:*:*
cpe:2.3:a:datarescue:ida_pro:5.1:*:*:*:*:*:*:*
EPSS
Процентиль: 88%
0.03965
Низкий
10 Critical
CVSS2
Дефекты
CWE-20
Связанные уязвимости
github
почти 4 года назад
The processor_request function in the debugger server for DataRescue IDA Pro 5.0 and 5.1 does not verify that authentication has taken place before invoking the perform_request function, which allows remote attackers to perform unauthorized actions.
EPSS
Процентиль: 88%
0.03965
Низкий
10 Critical
CVSS2
Дефекты
CWE-20