Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-25342

Опубликовано: 20 апр. 2022
Источник: nvd
CVSS3: 8.1
CVSS2: 5.5
EPSS Низкий

Описание

An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Broken Access Control. It does not properly validate requests for access to data and functionality under the /mngset/authset path. By not verifying permissions for access to resources, it allows a potential attacker to view pages that are not allowed.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:olivetti:d-color_mf3555_firmware:2xd_s000.002.271:*:*:*:*:*:*:*
cpe:2.3:h:olivetti:d-color_mf3555:-:*:*:*:*:*:*:*

EPSS

Процентиль: 37%
0.00164
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8.1
github
почти 4 года назад

An issue was discovered on Kyocera d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Broken Access Control. It does not properly validate requests for access to data and functionality under the /mngset/authset path. By not verifying permissions for access to resources, it allows a potential attacker to view pages that are not allowed.

EPSS

Процентиль: 37%
0.00164
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-862