Описание
Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- ProductVendor Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- ProductVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:sma:sunny_tripower_firmware:3.10.16.r:*:*:*:*:*:*:*
cpe:2.3:h:sma:sunny_tripower:5.0:*:*:*:*:*:*:*
EPSS
Процентиль: 91%
0.06286
Низкий
8.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-639
Связанные уязвимости
CVSS3: 8.1
github
почти 4 года назад
Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
EPSS
Процентиль: 91%
0.06286
Низкий
8.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-639