5.9
CVE-2019-13467
- EPSS 0.24%
- Veröffentlicht 30.09.2019 19:15:08
- Zuletzt bearbeitet 21.11.2024 04:24:57
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are potentially vulnerable to man-in-the-middle attacks when the applications download resources from the Dashboard web service. This vulnerability may allow an attacker to substitute downloaded resources with arbitrary files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sandisk ≫ Ssd Dashboard Version < 2.5.1.0
Westerndigital ≫ Ssd Dashboard Version < 2.5.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.441 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|