9.8
CVE-2023-37522
- EPSS 0.14%
- Veröffentlicht 16.01.2024 16:15:11
- Zuletzt bearbeitet 21.11.2024 08:11:51
- Quelle psirt@hcl.com
- CVE-Watchlists
- Unerledigt
HCL BigFix OSD Bare Metal Server WebUI is affected by missing or insecure tags
HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker to execute a malicious script on the user's browser.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltechsw ≫ Bigfix Bare Osd Metal Server Webui Version < 311.28
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.348 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| psirt@hcl.com | 5.6 | 2.2 | 3.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
|