5.9
CVE-2019-13467
- EPSS 0.24%
- Published 30.09.2019 19:15:08
- Last modified 21.11.2024 04:24:57
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are potentially vulnerable to man-in-the-middle attacks when the applications download resources from the Dashboard web service. This vulnerability may allow an attacker to substitute downloaded resources with arbitrary files.
Data is provided by the National Vulnerability Database (NVD)
Sandisk ≫ Ssd Dashboard Version < 2.5.1.0
Westerndigital ≫ Ssd Dashboard Version < 2.5.1.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.24% | 0.441 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|