Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-20649

Опубликовано: 12 фев. 2021
Источник: nvd
CVSS3: 4.8
CVSS2: 5.8
EPSS Низкий

Описание

ELECOM WRC-300FEBK-S contains an improper certificate validation vulnerability. Via a man-in-the-middle attack, an attacker may alter the communication response. As a result, an arbitrary OS command may be executed on the affected device.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:elecom:wrc-300febk-s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-300febk-s:-:*:*:*:*:*:*:*

EPSS

Процентиль: 28%
0.001
Низкий

4.8 Medium

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-295

Связанные уязвимости

github
больше 3 лет назад

ELECOM WRC-300FEBK-S contains an improper certificate validation vulnerability. Via a man-in-the-middle attack, an attacker may alter the communication response. As a result, an arbitrary OS command may be executed on the affected device.

EPSS

Процентиль: 28%
0.001
Низкий

4.8 Medium

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-295