Описание
Directory traversal vulnerability in the web server on Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allows remote attackers to bypass authentication, and write to a configuration file or trigger a calibration or test, via unspecified vectors.
Ссылки
- Third Party AdvisoryUS Government Resource
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 2.13b1 (включая)Версия до 1.13b1 (включая)
Одно из
cpe:2.3:o:honeywell:midas_black_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:honeywell:midas_firmware:*:*:*:*:*:*:*:*
EPSS
Процентиль: 52%
0.00296
Низкий
8.6 High
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 8.6
github
больше 3 лет назад
Directory traversal vulnerability in the web server on Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allows remote attackers to bypass authentication, and write to a configuration file or trigger a calibration or test, via unspecified vectors.
EPSS
Процентиль: 52%
0.00296
Низкий
8.6 High
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-22