8.8
CVE-2023-34672
- EPSS 0.08%
- Veröffentlicht 23.06.2023 19:15:09
- Zuletzt bearbeitet 05.12.2024 15:15:07
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Improper Access Control leads to adding a high-privilege user affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting user's role within the admin profile. An attack could occur over the public Internet in some cases.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Elenos ≫ Etg150 Firmware Version3.12
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.229 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-281 Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.