A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain access to the protected resource. If the same passwords were used for other resources, further such assets may be compromised.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:LRedlion Da50n
HWRedlionwszystkie wersjeRedlion Da50n Firmware
OSRedlionwszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Powiązane podatności
CVE-2022-1039CRITICAL9.6PL ✓ten sam produkt
Słabe hasła w Red Lion DA50N umożliwiają przejęcie urządzenia
CVE-2022-26516HIGH8.4ten sam produkt
Authorized users may install a maliciously modified package file when updating the device via the web user int...
CVE-2020-27285CRITICAL9.1PL ✓ten sam vendor
Red Lion Crimson 3.1 — dostęp do bazy danych bez uwierzytelnienia
CVE-2020-16204CRITICAL9.8PL ✓ten sam vendor
Ukryty interfejs w Red Lion N-Tron 702-W umożliwia wykonanie komend jako root
CVE-2020-16206CRITICAL9.0PL ✓ten sam vendor
Stored XSS umożliwiający RCE w Red Lion N-Tron 702-W / 702M12-W