Описание
A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated attacker on the network to delete arbitrary files on the system or render the system unusable by conducting a Denial of Service attack.
Ссылки
- MitigationThird Party AdvisoryUS Government Resource
- PatchThird Party Advisory
- MitigationThird Party AdvisoryUS Government Resource
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.4.1 (включая)Версия до 2.80 (включая)
Одно из
cpe:2.3:a:johnsoncontrols:victor_web_client:*:*:*:*:*:*:*:*
cpe:2.3:a:tyco:c-cure_web_client:*:*:*:*:*:*:*:*
EPSS
Процентиль: 76%
0.00977
Низкий
7.1 High
CVSS3
8.1 High
CVSS3
7.8 High
CVSS2
Дефекты
CWE-285
CWE-732
Связанные уязвимости
CVSS3: 8.1
github
больше 3 лет назад
A vulnerability in victor Web Client versions up to and including v5.4.1 could allow a remote unauthenticated attacker to delete arbitrary files on the system or render the system unusable by conducting a Denial of Service attack.
EPSS
Процентиль: 76%
0.00977
Низкий
7.1 High
CVSS3
8.1 High
CVSS3
7.8 High
CVSS2
Дефекты
CWE-285
CWE-732