Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-43269

Опубликовано: 20 янв. 2022
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config (PAC) file, leading to arbitrary code execution. This affects Incydr Basic, Advanced, and Gov F1; CrashPlan Cloud; and CrashPlan for Small Business. (Incydr Professional and Enterprise are unaffected.)

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:code42:code42:*:*:*:*:*:*:*:*
Версия до 8.8.0 (исключая)

EPSS

Процентиль: 64%
0.00466
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
github
около 4 лет назад

In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config (PAC) file, leading to arbitrary code execution. This affects Incydr Basic, Advanced, and Gov F1; CrashPlan Cloud; and CrashPlan for Small Business. (Incydr Professional and Enterprise are unaffected.)

EPSS

Процентиль: 64%
0.00466
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-94