Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-12310

Опубликовано: 03 июн. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 5
EPSS Низкий

Описание

ExaGrid appliances with firmware version v4.8.1.1044.P50 have a /monitor/data/Upgrade/ directory traversal vulnerability, which allows remote attackers to view and retrieve verbose logging information. Files within this directory were observed to contain sensitive run-time information, including Base64 encoded 'support' credentials, leading to administrative access of the device.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:exagrid:backup_appliance_firmware:48.1.1044.p50:*:*:*:*:*:*:*
cpe:2.3:h:exagrid:backup_appliance:-:*:*:*:*:*:*:*

EPSS

Процентиль: 75%
0.0088
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

ExaGrid appliances with firmware version v4.8.1.1044.P50 have a /monitor/data/Upgrade/ directory traversal vulnerability, which allows remote attackers to view and retrieve verbose logging information. Files within this directory were observed to contain sensitive run-time information, including Base64 encoded 'support' credentials, leading to administrative access of the device.

EPSS

Процентиль: 75%
0.0088
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22