Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

fstec логотип

BDU:2024-09952

почти 2 года назад

Уязвимость сервера сетевой установки Cobbler, связанная с недостатками процедуры аутентификации, позволяющая нарушителю получить полный доступ к серверу

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2024-47533

почти 2 года назад

Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2024-47533

почти 2 года назад

Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2024-47533

почти 2 года назад

Cobbler, a Linux installation server that allows for rapid setup of ne ...

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2024:0382-1

почти 2 года назад

Security update for cobbler

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2024:0370-1

почти 2 года назад

Security update for cobbler

EPSS: Низкий
github логотип

GHSA-m26c-fcgh-cp6h

почти 2 года назад

cobbler allows anyone to connect to cobbler XML-RPC server with known password and make changes

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-09952

Уязвимость сервера сетевой установки Cobbler, связанная с недостатками процедуры аутентификации, позволяющая нарушителю получить полный доступ к серверу

CVSS3: 9.8
4%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-47533

Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.

CVSS3: 9.8
4%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-47533

Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.

CVSS3: 9.8
4%
Низкий
почти 2 года назад
debian логотип
CVE-2024-47533

Cobbler, a Linux installation server that allows for rapid setup of ne ...

CVSS3: 9.8
4%
Низкий
почти 2 года назад
suse-cvrf логотип
openSUSE-SU-2024:0382-1

Security update for cobbler

4%
Низкий
почти 2 года назад
suse-cvrf логотип
openSUSE-SU-2024:0370-1

Security update for cobbler

4%
Низкий
почти 2 года назад
github логотип
GHSA-m26c-fcgh-cp6h

cobbler allows anyone to connect to cobbler XML-RPC server with known password and make changes

CVSS3: 9.8
4%
Низкий
почти 2 года назад

Уязвимостей на страницу