Описание
In Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a new functionality appears that could allow users to execute arbitrary commands on the hub device.
Ссылки
- Third Party AdvisoryUS Government Resource
- Release Notes
- Third Party AdvisoryUS Government Resource
- Release Notes
Уязвимые конфигурации
Конфигурация 1Версия до 7.3.0 (исключая)
Одновременно
cpe:2.3:a:snapone:orvc:*:*:*:*:*:pro:*:*
cpe:2.3:h:snapone:ovrc-300-pro:-:*:*:*:*:*:*:*
EPSS
Процентиль: 13%
0.00043
Низкий
8.3 High
CVSS3
7.2 High
CVSS3
Дефекты
CWE-912
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 8.3
github
больше 2 лет назад
In Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a new functionality appears that could allow users to execute arbitrary commands on the hub device.
EPSS
Процентиль: 13%
0.00043
Низкий
8.3 High
CVSS3
7.2 High
CVSS3
Дефекты
CWE-912
NVD-CWE-noinfo