Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-48974

Опубликовано: 14 нояб. 2024
Источник: nvd
CVSS3: 9.3
EPSS Низкий

Описание

The ventilator does not perform proper file integrity checks when adopting firmware updates. This makes it possible for an attacker to force unauthorized changes to the device's configuration settings and/or compromise device functionality by pushing a compromised/illegitimate firmware file. This could disrupt the function of the device and/or cause unauthorized information disclosure.

EPSS

Процентиль: 18%
0.00056
Низкий

9.3 Critical

CVSS3

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 9.3
github
около 1 года назад

The ventilator does not perform proper file integrity checks when adopting firmware updates. This makes it possible for an attacker to force unauthorized changes to the device's configuration settings and/or compromise device functionality by pushing a compromised/illegitimate firmware file. This could disrupt the function of the device and/or cause unauthorized information disclosure.

EPSS

Процентиль: 18%
0.00056
Низкий

9.3 Critical

CVSS3

Дефекты

CWE-494