Описание
Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitrary commands with administrative privileges by retrieving credentials from this file.
Ссылки
- https://poppopretn.com/2017/11/30/public-disclosure-firmware-vulnerabilities-in-ismartalarm-cubeone/ExploitThird Party Advisory
- https://poppopretn.com/2017/11/30/public-disclosure-firmware-vulnerabilities-in-ismartalarm-cubeone/ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.2.4.8 (включая)
Одновременно
cpe:2.3:o:ismartalarm:cubeone_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ismartalarm:cubeone:-:*:*:*:*:*:*:*
EPSS
Процентиль: 68%
0.00557
Низкий
9.8 Critical
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitrary commands with administrative privileges by retrieving credentials from this file.
EPSS
Процентиль: 68%
0.00557
Низкий
9.8 Critical
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200