Описание
A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that could allow an attacker to use a crafted webpage to obtain remote access to the system.
Ссылки
- ProductVendor Advisory
- ExploitThird Party Advisory
- ProductVendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.15.9 (исключая)
cpe:2.3:a:schneider-electric:c-bus_toolkit:*:*:*:*:*:*:*:*
EPSS
Процентиль: 80%
0.01426
Низкий
5.7 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-306
Связанные уязвимости
github
больше 3 лет назад
A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that could allow an attacker to use a crafted webpage to obtain remote access to the system.
EPSS
Процентиль: 80%
0.01426
Низкий
5.7 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-306