A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually restored.
CVE Status: Modified
Attribute | Value |
---|---|
Attack Complexity | LOW |
Attack Vector | NETWORK |
Availability Impact | HIGH |
Base Score | 6.8 |
Base Severity | MEDIUM |
Confidentiality Impact | HIGH |
Integrity Impact | HIGH |
Privileges Required | HIGH |
Scope | UNCHANGED |
User Interaction | REQUIRED |
Vector String | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Exploitability Score | 0.9 |
Impact Score | 5.9 |
Source | [email protected] |
Type | Secondary |