8.2
CVE-2022-47554
- EPSS 0.11%
- Veröffentlicht 19.09.2023 13:16:19
- Zuletzt bearbeitet 21.11.2024 07:32:10
- Quelle cve-coordination@incibe.es
- CVE-Watchlists
- Unerledigt
Exposure of sensitive information in ekorCCP and ekorRCI, potentially allowing a remote attacker to obtain critical information from various .xml files, including .xml files containing credentials, without being authenticated within the web server.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ormazabal ≫ Ekorrci Firmware Version601j
Ormazabal ≫ Ekorccp Firmware Version601j
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.304 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| cve-coordination@incibe.es | 8.2 | 3.9 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.