Описание
ScaleFusion 10.5.2 does not properly limit users to the Edge application because file downloads can occur. NOTE: the vendor's position is "Not vulnerable if the default Windows device profile configuration is used which utilizes modern management with website allow-listing rules."
Ссылки
- Vendor Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:a:scalefusion:scalefusion:10.5.2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
EPSS
Процентиль: 47%
0.00238
Низкий
4.6 Medium
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-286
Связанные уязвимости
CVSS3: 4.6
github
около 2 лет назад
ScaleFusion 10.5.2 does not properly limit users to the Edge application because file downloads can occur.
EPSS
Процентиль: 47%
0.00238
Низкий
4.6 Medium
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-286