Логотип exploitDog
bind:CVE-2020-10548
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-10548

Количество 2

Количество 2

nvd логотип

CVE-2020-10548

больше 5 лет назад

rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-59cr-f2p3-c96w

больше 3 лет назад

rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-10548

rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVSS3: 9.8
93%
Критический
больше 5 лет назад
github логотип
GHSA-59cr-f2p3-c96w

rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

93%
Критический
больше 3 лет назад

Уязвимостей на страницу