Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-14003

Опубликовано: 11 окт. 2017
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and prior versions. An improper authentication vulnerability has been identified, which, if exploited, would allow an attacker with the same IP address to bypass authentication by accessing a specific uniform resource locator.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:lavalink:ether-serial_link_firmware:*:*:*:*:*:*:*:*
Версия до 6.01.00\/29.03.2007 (включая)
cpe:2.3:h:lavalink:ether-serial_link:-:*:*:*:*:*:*:*

EPSS

Процентиль: 81%
0.01493
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-290
CWE-287

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and prior versions. An improper authentication vulnerability has been identified, which, if exploited, would allow an attacker with the same IP address to bypass authentication by accessing a specific uniform resource locator.

EPSS

Процентиль: 81%
0.01493
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-290
CWE-287