Описание
EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (such as in CVE-2021-27513 exploitation).
Ссылки
- ExploitThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:eyesofnetwork:eyesofnetwork:5.3-10:*:*:*:*:*:*:*
EPSS
Процентиль: 94%
0.13672
Средний
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-307
Связанные уязвимости
github
больше 3 лет назад
EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (such as in CVE-2021-27513 exploitation).
EPSS
Процентиль: 94%
0.13672
Средний
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-307