From ac87976a84725930dc13434d6feca51feb071d12 Mon Sep 17 00:00:00 2001 From: GitHub Action Date: Sat, 26 Mar 2022 09:11:31 +0000 Subject: [PATCH] Auto Generated CVE annotations [Sat Mar 26 09:11:31 UTC 2022] :robot: --- cves/2021/CVE-2021-45967.yaml | 7 ++++++- cves/2021/CVE-2021-45968.yaml | 5 +++++ 2 files changed, 11 insertions(+), 1 deletion(-) diff --git a/cves/2021/CVE-2021-45967.yaml b/cves/2021/CVE-2021-45967.yaml index f47246470d..63dd9fdcfb 100644 --- a/cves/2021/CVE-2021-45967.yaml +++ b/cves/2021/CVE-2021-45967.yaml @@ -3,13 +3,18 @@ id: CVE-2021-45967 info: name: Pascom CPS SSRF author: dwisiswant0 - severity: high + severity: critical description: | Pascom version packaged with Cloud Phone System (CPS) versions before 7.20 contains a known SSRF issue reference: - https://kerbit.io/research/read/blog/4 tags: cve,cve2021,pascom,lfi + classification: + cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H + cvss-score: 9.80 + cve-id: CVE-2021-45967 + cwe-id: CWE-918 requests: - method: GET diff --git a/cves/2021/CVE-2021-45968.yaml b/cves/2021/CVE-2021-45968.yaml index 3b516b9b3f..3cf2c2d6fa 100644 --- a/cves/2021/CVE-2021-45968.yaml +++ b/cves/2021/CVE-2021-45968.yaml @@ -10,6 +10,11 @@ info: reference: - https://kerbit.io/research/read/blog/4 tags: cve,cve2021,pascom,lfi + classification: + cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N + cvss-score: 7.50 + cve-id: CVE-2021-45968 + cwe-id: CWE-22 requests: - raw: