Логотип exploitDog
bind:CVE-2020-10546
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-10546

Количество 2

Количество 2

nvd логотип

CVE-2020-10546

больше 5 лет назад

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-9xcw-ph39-7c5x

больше 3 лет назад

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-10546

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVSS3: 9.8
91%
Критический
больше 5 лет назад
github логотип
GHSA-9xcw-ph39-7c5x

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

91%
Критический
больше 3 лет назад

Уязвимостей на страницу