9.8
CVE-2023-22581
- EPSS 0.17%
- Veröffentlicht 24.04.2023 09:15:09
- Zuletzt bearbeitet 21.11.2024 07:45:00
- Quelle csirt@divd.nl
- CVE-Watchlists
- Unerledigt
White Rabbit Switch contains a vulnerability which makes it possible for an attacker to perform system commands under the context of the web application (the default installation makes the webserver run as the root user).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Home.Cern ≫ White Rabbit Switch Firmware Version <= 6.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.384 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| csirt@divd.nl | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.