Описание
A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacker to execute arbitrary code on the system.
Ссылки
- MitigationThird Party AdvisoryUS Government Resource
- Permissions Required
- MitigationThird Party AdvisoryUS Government Resource
- Permissions Required
Уязвимые конфигурации
Одновременно
Одновременно
Одновременно
EPSS
9.8 Critical
CVSS3
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
Связанные уязвимости
A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacker to execute arbitrary code on the system.
Уязвимость микропрограммного обеспечения сервера синхронизации точного времени Reason RT430/RT434 GNSS Grandmaster Clock, связанная с возможностью внедрения кода, позволяющая нарушителю выполнить произвольный код
EPSS
9.8 Critical
CVSS3
8.8 High
CVSS3
9 Critical
CVSS2