Home
HIGH: 7.6 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/AU:Y/R:U/RE:M/U:GreenDefault status
affected
16.0.0 (cpe)
affected
15.0.0 (cpe)
affected
12.0.0 (cpe)
affected
Description
Some payload elements of the messages sent between two stations in a networking architecture are not properly checked on the receiving station allowing an attacker to execute unauthorized commands in the application.
Problem types
CWE-940 Improper Verification of Source of a Communication Channel
CWE-1288 Improper Validation of Consistency within Input
Product status
16.0.0 (cpe)
15.0.0 (cpe)
12.0.0 (cpe)
Credits
Guillaume André (Synacktiv)
Pierre Gertner (Synacktiv)
References
www.pcvue.com/security/