9
CVE-2016-7786
- EPSS 6.98%
- Veröffentlicht 07.04.2017 21:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demonstrated by a request for Licenseinformation.jsp. This is fixed in 10.6.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sophos ≫ Cyberoam Cr25ing Utm Firmware Version 10.6.2 Update mr-5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.98% | 0.933 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|
https://infosecninja.blogspot.in/2017/04/cve-2016-7786-sophos-cyberoam-utm.html
https://www.exploit-db.com/exploits/44469/