9.8
CVE-2023-22577
- EPSS 0.21%
- Veröffentlicht 24.04.2023 09:15:09
- Zuletzt bearbeitet 21.11.2024 07:44:59
- Quelle csirt@divd.nl
- CVE-Watchlists
- Unerledigt
Within White Rabbit Switch it's possible as an unauthenticated user to retrieve sensitive information such as password hashes and the SNMP community strings.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Home.Cern ≫ White Rabbit Switch Firmware Version <= 6.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.429 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| csirt@divd.nl | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.