Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-6729

Опубликовано: 17 окт. 2024
Источник: nvd
CVSS3: 7.3
EPSS Низкий

Описание

Nokia SR OS routers allow read-write access to the entire file system via SFTP or SCP for users configured with "access console." Consequently, a low privilege authenticated user with "access console" can read or replace the router configuration file as well as other files stored in the Compact Flash or SD card without using CLI commands. This type of attack can lead to a compromise or denial of service of the router after the system is rebooted.

EPSS

Процентиль: 10%
0.00035
Низкий

7.3 High

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.3
github
больше 1 года назад

Nokia SR OS routers allow read-write access to the entire file system via SFTP or SCP for users configured with "access console." Consequently, a low privilege authenticated user with "access console" can read or replace the router configuration file as well as other files stored in the Compact Flash or SD card without using CLI commands. This type of attack can lead to a compromise or denial of service of the router after the system is rebooted.

EPSS

Процентиль: 10%
0.00035
Низкий

7.3 High

CVSS3

Дефекты

CWE-732