← Retour à la recherche de CVE

CVE-2026-2417

Pharos Controls Mosaic Show Controller

Description

A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 could allow an unauthenticated attacker to bypass authentication and execute arbitrary commands with root privileges.

CVSS 9.3EPSS 0.573%Risque 0.98
Voir la source
Publication
2026-03-24 19:16:51
Versions concernées
<=2.15.3
Type
Micrologiciel
Vecteur
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X