Описание
AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gain privileges via a crafted cookie that triggers memory corruption, aka the "Misfortune Cookie" vulnerability.
Ссылки
- Technical DescriptionThird Party Advisory
- Mailing ListThird Party Advisory
- Vendor Advisory
- Third Party AdvisoryUS Government Resource
- Third Party Advisory
- Technical DescriptionThird Party Advisory
- Mailing ListThird Party Advisory
- Vendor Advisory
- Third Party AdvisoryUS Government Resource
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.07 (включая)
cpe:2.3:a:allegrosoft:rompager:*:*:*:*:*:*:*:*
EPSS
Процентиль: 99%
0.88684
Высокий
10 Critical
CVSS2
Дефекты
CWE-17
Связанные уязвимости
github
больше 3 лет назад
AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gain privileges via a crafted cookie that triggers memory corruption, aka the "Misfortune Cookie" vulnerability.
EPSS
Процентиль: 99%
0.88684
Высокий
10 Critical
CVSS2
Дефекты
CWE-17