Janitza UMG 508, 509, 511, 604, and 605 devices allow remote attackers to obtain sensitive network-connection information via a request to UDP port (1) 1234 or (2) 1235.
CVSS Vector
AV:N/AC:L/Au:N/C:P/I:N/A:NJanitza Umg 508
HWJanitzaall versionsJanitza Umg 509
HWJanitzaall versionsJanitza Umg 511
HWJanitzaall versionsJanitza Umg 604
HWJanitzaall versionsJanitza Umg 605
HWJanitzaall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2015-3968HIGH7.5same product
The FTP service on Janitza UMG 508, 509, 511, 604, and 605 devices has a default password, which makes it easi...
CVE-2015-3971HIGH7.5same product
The debug interface on Janitza UMG 508, 509, 511, 604, and 605 devices does not require authentication, which ...
CVE-2015-3972HIGH10.0same product
The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authen...
CVE-2015-3967MEDIUM6.8same product
Cross-site request forgery (CSRF) vulnerability on Janitza UMG 508, 509, 511, 604, and 605 devices allows remo...
CVE-2015-3970MEDIUM4.3same product
Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Janitza UMG 508, 509, 511, 604, an...