An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the communication to the web service is unencrypted via http. An attacker is able to intercept and sniff communication to the web service.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NVzug Combi Stream Mslq
HWVzugall versionsVzug Combi Stream Mslq Firmware
OSVzug< ethernet_r07< wlan_r05
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2019-17215CRITICAL9.8PL ✓same product
Brak ochrony przed brute-force w urządzeniach V-Zug Combi-Steam MSLQ
CVE-2019-17216CRITICAL9.8PL ✓same product
V-Zug Combi-Steam MSLQ: słabe hashowanie haseł z użyciem MD5
CVE-2019-17217HIGH8.8same product
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no...
CVE-2019-17219HIGH8.8same product
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default,...