Логотип exploitDog
bind:CVE-2023-48427
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-48427

Количество 3

Количество 3

nvd логотип

CVE-2023-48427

около 2 лет назад

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the UMC server as well as to manipulate responses, potentially allowing an attacker to escalate privileges.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-ffrg-8pgr-8693

около 2 лет назад

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the UMC server as well as to manipulate responses, potentially allowing an attacker to escalate privileges.

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2024-00032

около 2 лет назад

Уязвимость веб-интерфейса программного обеспечения для управления сетевой инфраструктурой SINEC INS (Infrastructure Network Services), позволяющая нарушителю повысить свои привилегии

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-48427

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the UMC server as well as to manipulate responses, potentially allowing an attacker to escalate privileges.

CVSS3: 8.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-ffrg-8pgr-8693

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the UMC server as well as to manipulate responses, potentially allowing an attacker to escalate privileges.

CVSS3: 8.1
0%
Низкий
около 2 лет назад
fstec логотип
BDU:2024-00032

Уязвимость веб-интерфейса программного обеспечения для управления сетевой инфраструктурой SINEC INS (Infrastructure Network Services), позволяющая нарушителю повысить свои привилегии

CVSS3: 9.8
0%
Низкий
около 2 лет назад

Уязвимостей на страницу