Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-0451

Опубликовано: 26 янв. 2023
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Econolite EOS versions prior to 3.2.23 lack a password requirement for gaining “READONLY” access to log files and certain database and configuration files. One such file contains tables with MD5 hashes and usernames for all defined users in the control software, including administrators and technicians.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:econolite:eos:*:*:*:*:*:*:*:*

EPSS

Процентиль: 38%
0.00164
Низкий

7.5 High

CVSS3

Дефекты

CWE-284
NVD-CWE-Other

Связанные уязвимости

CVSS3: 7.5
github
больше 2 лет назад

All versions of Econolite EOS traffic control software are vulnerable to CWE-284: Improper Access Control, and lack a password requirement for gaining “READONLY” access to log files, as well as certain database and configuration files. One such file contains tables with message-digest algorithm 5 (MD5) hashes and usernames for all defined users in the control software, including administrators and technicians.

EPSS

Процентиль: 38%
0.00164
Низкий

7.5 High

CVSS3

Дефекты

CWE-284
NVD-CWE-Other