8.1

CVE-2018-15498

Exploit
YSoft SafeQ Server 6 allows a replay attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
YsoftSafeq Server Client Version6.0.13.1
   YsoftSafeq Server Version6.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.2% 0.64
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-294 Authentication Bypass by Capture-replay

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

https://herolab.usd.de/wp-content/uploads/sites/4/usd20180021.txt
Third Party Advisory
Exploit