Описание
X-Plane before 11.41 has multiple improper path validations that could allow reading and writing files from/to arbitrary paths (or a leak of OS credentials to a remote system) via crafted network packets. This could be used to execute arbitrary commands on the system.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 11.41 (исключая)
cpe:2.3:a:x-plane:x-plane:*:*:*:*:*:*:*:*
EPSS
Процентиль: 63%
0.00453
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-78
Связанные уязвимости
github
больше 3 лет назад
X-Plane 11.41 and earlier has multiple improper path validations that could allow reading and writing files from/to arbitrary paths (or a leak of OS credentials to a remote system) via crafted network packets. This could be used to execute arbitrary commands on the system.
EPSS
Процентиль: 63%
0.00453
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-78