Логотип exploitDog
bind:CVE-2020-17405
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-17405

Количество 3

Количество 3

nvd логотип

CVE-2020-17405

больше 5 лет назад

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Senstar Symphony 7.3.2.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSOAuth process. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10980.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-39c2-x5w3-56xm

больше 3 лет назад

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Senstar Symphony 7.3.2.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSOAuth process. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10980.

EPSS: Низкий
fstec логотип

BDU:2020-04727

больше 5 лет назад

Уязвимость процесса SSOAuth программного обеспечения платформы для управления системой видеонаблюдения Senstar Symphony, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-17405

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Senstar Symphony 7.3.2.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSOAuth process. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10980.

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
github логотип
GHSA-39c2-x5w3-56xm

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Senstar Symphony 7.3.2.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSOAuth process. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10980.

1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2020-04727

Уязвимость процесса SSOAuth программного обеспечения платформы для управления системой видеонаблюдения Senstar Symphony, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
1%
Низкий
больше 5 лет назад

Уязвимостей на страницу