Описание
The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API. NOTE: This may be a duplicate of CVE-2020-10176
Ссылки
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 2.21 (включая) до 2.31 (включая)
Одновременно
cpe:2.3:o:assaabloy:yale_wipc-303w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:assaabloy:yale_wipc-303w:-:*:*:*:*:*:*:*
EPSS
Процентиль: 93%
0.11128
Средний
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-78
Связанные уязвимости
CVSS3: 8.8
github
больше 3 лет назад
The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API.
EPSS
Процентиль: 93%
0.11128
Средний
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-78