Описание
The product M2M ETHERNET (FW Versions 2.22 and prior, ETH-FW Versions 1.01 and prior) is vulnerable in that an attacker can upload a malicious language file by bypassing the user authentication mechanism.
Ссылки
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryUS Government Resource
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 1.01 (включая)Версия до 2.22 (включая)
Одновременно
Одно из
cpe:2.3:o:abb:eth-fw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:abb:fw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:m2m_ethernet:-:*:*:*:*:*:*:*
EPSS
Процентиль: 20%
0.00063
Низкий
4.3 Medium
CVSS3
3.3 Low
CVSS2
Дефекты
CWE-287
CWE-287
Связанные уязвимости
CVSS3: 4.3
github
больше 3 лет назад
The product M2M ETHERNET (FW Versions 2.22 and prior, ETH-FW Versions 1.01 and prior) is vulnerable in that an attacker can upload a malicious language file by bypassing the user authentication mechanism.
EPSS
Процентиль: 20%
0.00063
Низкий
4.3 Medium
CVSS3
3.3 Low
CVSS2
Дефекты
CWE-287
CWE-287