An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no bruteforce protection (e.g., lockout) established. An attacker might be able to bruteforce the password to authenticate on the device.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HVzug Combi Stream Mslq
HWVzugall versionsVzug Combi Stream Mslq Firmware
OSVzug< ethernet_r07< wlan_r05
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2019-17216CRITICAL9.8PL ✓same product
V-Zug Combi-Steam MSLQ: słabe hashowanie haseł z użyciem MD5
CVE-2019-17218CRITICAL9.1PL ✓same product
V-Zug Combi-Steam MSLQ — niezaszyfrowana komunikacja HTTP z web service
CVE-2019-17217HIGH8.8same product
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no...
CVE-2019-17219HIGH8.8same product
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default,...