Описание
The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass authentication and (1) enumerate users, (2) reset passwords, or (3) manipulate IP filter restrictions via crafted "privileged commands."
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:tripwire:ip360:7.2.2:*:*:*:*:*:*:*
cpe:2.3:a:tripwire:ip360:7.2.4:*:*:*:*:*:*:*
cpe:2.3:a:tripwire:ip360:7.2.5:*:*:*:*:*:*:*
EPSS
Процентиль: 68%
0.00582
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass authentication and (1) enumerate users, (2) reset passwords, or (3) manipulate IP filter restrictions via crafted "privileged commands."
EPSS
Процентиль: 68%
0.00582
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-287