Логотип exploitDog
bind:CVE-2025-40830
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-40830

Количество 3

Количество 3

nvd логотип

CVE-2025-40830

9 дней назад

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorization checks for the file_transfer feature in ssmctl-client command. This could allow an authenticated, lowly privileged local attacker to read or write to any file on server or sensor.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-35cr-f3qc-gm6j

9 дней назад

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorization checks for the file_transfer feature in ssmctl-client command. This could allow an authenticated, lowly privileged local attacker to read or write to any file on server or sensor.

CVSS3: 6.7
EPSS: Низкий
fstec логотип

BDU:2025-15617

10 дней назад

Уязвимость функции file_transfer() программного обеспечения для обеспечения безопасности SINEC Security Monitor, позволяющая нарушителю получить доступ на чтение и запись произвольных файлов

CVSS3: 6.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-40830

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorization checks for the file_transfer feature in ssmctl-client command. This could allow an authenticated, lowly privileged local attacker to read or write to any file on server or sensor.

CVSS3: 6.7
0%
Низкий
9 дней назад
github логотип
GHSA-35cr-f3qc-gm6j

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorization checks for the file_transfer feature in ssmctl-client command. This could allow an authenticated, lowly privileged local attacker to read or write to any file on server or sensor.

CVSS3: 6.7
0%
Низкий
9 дней назад
fstec логотип
BDU:2025-15617

Уязвимость функции file_transfer() программного обеспечения для обеспечения безопасности SINEC Security Monitor, позволяющая нарушителю получить доступ на чтение и запись произвольных файлов

CVSS3: 6.7
0%
Низкий
10 дней назад

Уязвимостей на страницу