5.3

CVE-2018-9115

Exploit
Systematic SitaWare 6.4 SP2 does not validate input from other sources sufficiently. e.g., information utilizing the NVG interface. An attacker can freeze the Situational Layer, which means that the Situational Picture is no longer updated. Unfortunately, the user cannot notice until he tries to work with that layer.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SystematicincSitaware Version6.4 Updatesp2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.02% 0.924
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://exchange.xforce.ibmcloud.com/vulnerabilities/141099
VDB Entry
https://packetstormsecurity.com/files/146982
Third Party Advisory
Exploit
VDB Entry
https://www.exploit-db.com/exploits/44375/
Third Party Advisory
Exploit
VDB Entry