7.5
CVE-2021-46354
- EPSS 34.66%
- Veröffentlicht 09.02.2022 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:33:57
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site. The ability to send requests to other systems can allow the vulnerable server to filtrate the real IP of the web server or increase the attack surface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cybelesoft ≫ Thinfinity Virtualui Version2.1.28.0
Cybelesoft ≫ Thinfinity Virtualui Version2.1.32.1
Cybelesoft ≫ Thinfinity Virtualui Version2.5.26.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 34.66% | 0.968 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-668 Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.