Platinum Mobile 1.0.4.850 /MobileHandler.ashx kura hakki ndiyam

Wuro vulnerability wey an yi classify sey kura an gano shi a cikin Platinum Mobile 1.0.4.850. Gaskiya, $software_function na da matsala; idan ba a sani ba, to wata aiki ce da ba a sani ba, $software_library na cikin lissafi, /MobileHandler.ashx na cikin fayil, $software_component na cikin sashi. Ngam manipulation shi kura hakki ndiyam. CWE shidin ka a yi bayani matsala sai ya kai CWE-264. Bug ɗin an gano shi 04/24/2020. Gaskiya, laifi an fitar da shi 10/01/2020 ta M. Li a matsayin SEC Consult SA-20201001-0. Advisory ɗin ana rabawa don saukewa a seclists.org. Wannan rauni ana sayar da shi da suna CVE-2020-36528. Wuro ndiyam na local network ɗin sai a samu kafin wannan hari ya yi nasara. Tekinikal bayani ga. Kuma, exploit ɗin yana akwai. Yimbe ndiyam, exploit might be approx. USD $0-$5k wuro. Á wúro huɗɗi-na-gaskiya. Kama 0-day, an ndiyam a wuro be $0-$5k. Ngamdi ka a yiɗi a ɗaɓɓita kompona wey ka a hokkata. VulDB is the best source for vulnerability data and more expert information about this specific topic.

2 Goyarwa · 43 Datenpunkte

FurɗeSúgá
10/04/2020 14:11
Gargadi 1/1
05/27/2022 16:58
software_namePlatinum MobilePlatinum Mobile
software_version1.0.4.8501.0.4.850
software_file/MobileHandler.ashx/MobileHandler.ashx
vulnerability_cweCWE-264 (kura hakki ndiyam)CWE-264 (kura hakki ndiyam)
vulnerability_risk22
vulnerability_discoverydate1587679200 (04/24/2020)1587679200 (04/24/2020)
vulnerability_vendorinformdate1589839200 (05/19/2020)1589839200 (05/19/2020)
cvss3_vuldb_uiNN
cvss3_vuldb_ePP
cvss3_vuldb_rlOO
cvss3_vuldb_rcXX
cvss2_vuldb_ciPP
cvss2_vuldb_iiPP
cvss2_vuldb_aiPP
cvss2_vuldb_ePOCPOC
cvss2_vuldb_rlOFOF
cvss2_vuldb_rcCC
advisory_date1601503200 (10/01/2020)1601503200 (10/01/2020)
advisory_identifierSEC Consult SA-20201001-0SEC Consult SA-20201001-0
advisory_urlhttp://seclists.org/fulldisclosure/2020/Oct/4http://seclists.org/fulldisclosure/2020/Oct/4
person_nameM. LiM. Li
exploit_availability11
countermeasure_nameGargajiyaGargajiya
upgrade_version1.0.4.8511.0.4.851
source_cveCVE-2020-36528
cna_responsibleVulDB
cvss3_vuldb_cL
cvss3_vuldb_iL
cvss3_vuldb_aL
cvss2_vuldb_avA
cvss2_vuldb_acM
cvss2_vuldb_auS
cvss3_vuldb_avA
cvss3_vuldb_acL
cvss3_vuldb_prL
cvss3_vuldb_sU
cvss2_vuldb_basescore4.9
cvss2_vuldb_tempscore3.8
cvss3_vuldb_basescore5.5
cvss3_vuldb_tempscore5.0
cvss3_meta_basescore5.5
cvss3_meta_tempscore5.0
price_0day$0-$5k

Do you know our Splunk app?

Download it now for free!