Описание
WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 fails to validate user sessions, allowing unauthenticated attackers to read files from the underlying operating system and obtain directory listings.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:wipotec:comscale:4.3.29.21344:*:*:*:*:*:*:*
cpe:2.3:a:wipotec:comscale:4.4.12.723:*:*:*:*:*:*:*
EPSS
Процентиль: 39%
0.00169
Низкий
7.5 High
CVSS3
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 7.5
github
больше 2 лет назад
WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 fails to validate user sessions, allowing unauthenticated attackers to read files from the underlying operating system and obtain directory listings.
EPSS
Процентиль: 39%
0.00169
Низкий
7.5 High
CVSS3
Дефекты
CWE-200