An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the device does not enforce any authentication. An adjacent attacker is able to use the network interface without proper access control.
oryginał ENCVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HVzug Combi Stream Mslq
HWVzugwszystkie wersjeVzug Combi Stream Mslq Firmware
OSVzug< ethernet_r07< wlan_r05
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Powiązane podatności
CVE-2019-17215CRITICAL9.8PL ✓ten sam produkt
Brak ochrony przed brute-force w urządzeniach V-Zug Combi-Steam MSLQ
CVE-2019-17216CRITICAL9.8PL ✓ten sam produkt
V-Zug Combi-Steam MSLQ: słabe hashowanie haseł z użyciem MD5
CVE-2019-17218CRITICAL9.1PL ✓ten sam produkt
V-Zug Combi-Steam MSLQ — niezaszyfrowana komunikacja HTTP z web service
CVE-2019-17217HIGH8.8ten sam produkt
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no...