Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-35584

Опубликовано: 23 дек. 2020
Источник: nvd
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature. An attacker suitably positioned to view a legitimate user's network traffic could record and monitor their interactions with the web services and obtain any information the user supplies, including Administrator passwords and screen keys.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:mersive:solstice_pod_firmware:*:*:*:*:*:*:*:*
Версия до 3.0.3 (исключая)
cpe:2.3:h:mersive:solstice_pod:-:*:*:*:*:*:*:*

EPSS

Процентиль: 39%
0.00176
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-319

Связанные уязвимости

github
больше 3 лет назад

In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature. An attacker suitably positioned to view a legitimate user's network traffic could record and monitor their interactions with the web services and obtain any information the user supplies, including Administrator passwords and screen keys.

EPSS

Процентиль: 39%
0.00176
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-319