liftoffsoftware kayıtları
liftoffsoftware üreticisine ait 3 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
3 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-20184İstismar yok | GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection.liftoffsoftware · gateone · CWE-78 | Kritik9,8 | — | %2,7 | 14 Ara 2020 |
35İzleyin | CVE-2020-35736Kavram kanıtı | GateOne 1.1 allows arbitrary file download without authentication via /downloads/..liftoffsoftware · gateone · CWE-22 | Yüksek7,5 | — | %15,4 | 27 Ara 2020 |
21İzleyin | CVE-2020-19003İstismar yok | An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances uliftoffsoftware · gate one · CWE-290 | Orta5,3 | — | %0,8 | 6 Eki 2021 |
- CVE-2020-2018440Planlayın
GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection.
KritikCVSS 9,8İstismar yokEPSS %3liftoffsoftware · gateone14 Ara 2020
- CVE-2020-3573635İzleyin
GateOne 1.1 allows arbitrary file download without authentication via /downloads/..
YüksekCVSS 7,5Kavram kanıtıEPSS %15liftoffsoftware · gateone27 Ara 2020
- CVE-2020-1900321İzleyin
An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances u
OrtaCVSS 5,3İstismar yokEPSS %1liftoffsoftware · gate one6 Eki 2021