Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-16261

Опубликовано: 12 сент. 2019
Источник: nvd
CVSS3: 9.1
CVSS2: 8.5
EPSS Низкий

Описание

Tripp Lite PDUMH15AT 12.04.0053 and SU750XL 12.04.0052 devices allow unauthenticated POST requests to the /Forms/ directory, as demonstrated by changing the manager or admin password, or shutting off power to an outlet. NOTE: the vendor's position is that a newer firmware version, fixing this vulnerability, had already been released before this vulnerability report about 12.04.0053.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:tripplite:pdumh15at_firmware:12.04.0053:*:*:*:*:*:*:*
cpe:2.3:h:tripplite:pdumh15at:-:*:*:*:*:*:*:*

EPSS

Процентиль: 60%
0.00393
Низкий

9.1 Critical

CVSS3

8.5 High

CVSS2

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.1
github
больше 3 лет назад

Tripp Lite PDUMH15AT 12.04.0053 devices allow unauthenticated POST requests to the /Forms/ directory, as demonstrated by changing the manager or admin password, or shutting off power to an outlet. NOTE: the vendor's position is that a newer firmware version, fixing this vulnerability, had already been released before this vulnerability report about 12.04.0053.

EPSS

Процентиль: 60%
0.00393
Низкий

9.1 Critical

CVSS3

8.5 High

CVSS2

Дефекты

CWE-287