Описание
rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.9.4 (включая)
cpe:2.3:a:rconfig:rconfig:*:*:*:*:*:*:*:*
EPSS
Процентиль: 100%
0.92086
Критический
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-89
Связанные уязвимости
github
около 3 лет назад
rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.
EPSS
Процентиль: 100%
0.92086
Критический
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-89