7.2
CVE-2018-17931
- EPSS 0.04%
- Veröffentlicht 30.10.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:14
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
If an attacker has physical access to the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) they may be able to alter scripts, which may allow code execution with root privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Vecna ≫ Vgo Firmware Version <= 3.0.3.52164
Vecna ≫ Vgo Firmware Version3.0.3.53662
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.095 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 0.9 | 5.9 |
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.