← לוח פגיעויות

CVE-2026-0239

בינונית 6.5

תיאור (מקור, אנגלית)

An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with network access to the collector service to retrieve sensitive information.

מדדים

CVSS 3.1
6.5 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 4.0
4.9 (MEDIUM) מקור הציון: CNA CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-3/8/2026
CWE
CWE-497

מוצרים מושפעים

paloaltonetworks: chronosphere collector

קישורים