Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-3891

Опубликовано: 14 нояб. 2017
Источник: nvd
CVSS3: 8.1
CVSS3: 9.6
CVSS2: 6.8
EPSS Низкий

Описание

In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX SDP with QNet enabled on networks comprising two or more QNet nodes could allow an attacker to access local and remote files or take ownership of files on other QNX nodes regardless of permissions by executing commands targeting arbitrary nodes from a secondary QNX 6.6.0 QNet node.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:blackberry:qnx_software_development_platform:6.6.0:*:*:*:*:*:*:*

EPSS

Процентиль: 53%
0.00299
Низкий

8.1 High

CVSS3

9.6 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-923
CWE-863

Связанные уязвимости

CVSS3: 8.1
github
больше 3 лет назад

In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX SDP with QNet enabled on networks comprising two or more QNet nodes could allow an attacker to access local and remote files or take ownership of files on other QNX nodes regardless of permissions by executing commands targeting arbitrary nodes from a secondary QNX 6.6.0 QNet node.

EPSS

Процентиль: 53%
0.00299
Низкий

8.1 High

CVSS3

9.6 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-923
CWE-863