CVE-2023-26150

HIGH7.5EPSS 0.16%

asyncua Improper Authentication vulnerability

發布日:2023/10/3修改日:2024/2/16
也稱為:GHSA-2894-qcqf-g23gPYSEC-2023-189

描述

Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encryption and authentication. **Note:** This issue is a result of missing checks for services that require an active session.

受影響套件(2)

  • PyPI/asyncuafrom 0, < 0.9.96
  • PyPI/asyncuafrom 0, < b4106dfd5037423c9d1810b48a97296b59cde513, < 2be7ce80df05de8d6c6ae1ebce6fa2bb7147844a | from 0, < 0.9.96

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

參考連結(10)