Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-6044

Опубликовано: 30 июн. 2017
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can be accessed without authentication, which may allow a remote attacker to perform sensitive functions including arbitrary file upload, file download, and device reboot.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:sierra_wireless:airlink_raven_xe_firmware:*:*:*:*:*:*:*:*
Версия до - (включая)
cpe:2.3:h:sierra_wireless:airlink_raven_xe:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:sierra_wireless:airlink_raven_xt_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:sierra_wireless:airlink_raven_xt:-:*:*:*:*:*:*:*

EPSS

Процентиль: 92%
0.0769
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-285
CWE-306

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can be accessed without authentication, which may allow a remote attacker to perform sensitive functions including arbitrary file upload, file download, and device reboot.

EPSS

Процентиль: 92%
0.0769
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-285
CWE-306