Описание
Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, then click on the login button, and it will redirect you to /home.jsp without any authentication.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 21.1.30 (исключая)Версия до 21.4.45 (исключая)
Одно из
cpe:2.3:a:sysaid:sysaid:*:*:*:*:cloud:*:*:*
cpe:2.3:a:sysaid:sysaid:*:*:*:*:on-premises:*:*:*
EPSS
Процентиль: 45%
0.00229
Низкий
7 High
CVSS3
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, then click on the login button, and it will redirect you to /home.jsp without any authentication.
EPSS
Процентиль: 45%
0.00229
Низкий
7 High
CVSS3
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-287