Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-6777

Опубликовано: 14 янв. 2021
Источник: nvd
CVSS3: 4.8
CVSS2: 3.5
EPSS Низкий

Описание

A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAESENSA until and including version 1.10 allows an authenticated remote attacker with admin privileges to mount a stored Cross-Site-Scripting (XSS) attack against another user. When the victim logs into the management interface, the stored script code is executed in the context of his browser. A successful exploit would allow an attacker to interact with the management interface with the privileges of the victim. However, as the attacker already needs admin privileges, there is no additional impact on the management interface itself.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:bosch:praesideo_firmware:*:*:*:*:*:*:*:*
Версия до 4.41 (включая)
cpe:2.3:h:bosch:praesideo:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:bosch:praesensa_firmware:*:*:*:*:*:*:*:*
Версия до 1.10 (включая)
cpe:2.3:h:bosch:praesensa:-:*:*:*:*:*:*:*

EPSS

Процентиль: 34%
0.00136
Низкий

4.8 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79
CWE-79

Связанные уязвимости

github
больше 3 лет назад

A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAESENSA until and including version 1.10 allows an authenticated remote attacker with admin privileges to mount a stored Cross-Site-Scripting (XSS) attack against another user. When the victim logs into the management interface, the stored script code is executed in the context of his browser. A successful exploit would allow an attacker to interact with the management interface with the privileges of the victim. However, as the attacker already needs admin privileges, there is no additional impact on the management interface itself.

EPSS

Процентиль: 34%
0.00136
Низкий

4.8 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79
CWE-79