Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-40146

Опубликовано: 17 апр. 2024
Источник: nvd
CVSS3: 6.8
CVSS3: 9.8
EPSS Низкий

Описание

A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command line argument can lead to a limited-shell escape and elevated capabilities. An attacker can authenticate with hard-coded credentials and execute unblocked default busybox functionality to trigger this vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:peplink:smart_reader_firmware:1.2.0:*:*:*:*:*:*:*
cpe:2.3:h:peplink:smart_reader:-:*:*:*:*:*:*:*

EPSS

Процентиль: 77%
0.01013
Низкий

6.8 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-77
CWE-798

Связанные уязвимости

CVSS3: 6.8
github
почти 2 года назад

A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command line argument can lead to a limited-shell escape and elevated capabilities. An attacker can authenticate with hard-coded credentials and execute unblocked default busybox functionality to trigger this vulnerability.

EPSS

Процентиль: 77%
0.01013
Низкий

6.8 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-77
CWE-798