Логотип exploitDog
bind:CVE-2023-53908
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-53908

Количество 2

Количество 2

nvd логотип

CVE-2023-53908

около 2 месяцев назад

HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access role through XML-based NETCONF configuration. Attackers can send crafted XML payloads to the /mops_data endpoint with a specific role value to elevate their user privileges to administrative level.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-px84-m7h4-295j

около 2 месяцев назад

HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access role through XML-based NETCONF configuration. Attackers can send crafted XML payloads to the /mops_data endpoint with a specific role value to elevate their user privileges to administrative level.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-53908

HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access role through XML-based NETCONF configuration. Attackers can send crafted XML payloads to the /mops_data endpoint with a specific role value to elevate their user privileges to administrative level.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-px84-m7h4-295j

HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access role through XML-based NETCONF configuration. Attackers can send crafted XML payloads to the /mops_data endpoint with a specific role value to elevate their user privileges to administrative level.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу