Описание
lte-pic32-writer is a writer for PIC32 devices. In versions 0.0.1 and prior, those who use sendto.txt are vulnerable to attackers who known the IMEI reading the sendto.txt. The sendto.txt file can contain the SNS(such as slack and zulip) URL and API key. As of time of publication, a patch is not yet available. As workarounds, avoid using sendto.txt or use .htaccess to block access to sendto.txt.
Уязвимые конфигурации
Конфигурация 1Версия до 0.0.3 (исключая)
cpe:2.3:a:pajip:lte-pic32-writer:*:*:*:*:*:*:*:*
EPSS
Процентиль: 42%
0.00201
Низкий
8.9 High
CVSS3
7.5 High
CVSS3
Дефекты
CWE-538
NVD-CWE-noinfo
EPSS
Процентиль: 42%
0.00201
Низкий
8.9 High
CVSS3
7.5 High
CVSS3
Дефекты
CWE-538
NVD-CWE-noinfo