Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-37378

Опубликовано: 03 фев. 2023
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

Cross Site Scripting (XSS) vulnerability in Teradek Cube and Cube Pro firmware version 7.3.x and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:teradke:cube_firmware:*:*:*:*:*:*:*:*
Версия от 7.3.0 (включая) до 7.3.19 (включая)
cpe:2.3:h:teradke:cube:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:teradke:cube_pro_firmware:*:*:*:*:*:*:*:*
Версия от 7.3.0 (включая) до 7.3.16 (включая)
cpe:2.3:h:teradke:cube_pro:-:*:*:*:*:*:*:*

EPSS

Процентиль: 20%
0.00062
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 5.4
github
около 3 лет назад

** UNSUPPORTED WHEN ASSIGNED ** Cross Site Scripting (XSS) vulnerability in Teradek Cube and Cube Pro firmware version 7.3.x and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.

EPSS

Процентиль: 20%
0.00062
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79