CRITICAL🇵🇱 Wersja polska

CVE-2024-8878

CVSS 10.0v4.0pub. 2024-09-25upd. 2025-11-04

The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: through 4.05.

🤖 AI Analysis
How it works

The vulnerability (CWE-640) results from improper implementation of the password recovery mechanism. An attacker can use the password reset procedure in such a way as to set a new administrator password without the need to verify identity. Network access to the device's network is the only necessary condition to carry out the attack — no prior credentials or user interaction are required.

Impact

The attacker gains full administrative control over the Riello Netman 204 device, which enables changing its configuration, disrupting UPS operation, and potentially cutting off power to critical infrastructure.

Mitigation & patch

Apply patches available from the manufacturer according to the references provided. Until updates are applied, it is recommended to isolate Netman 204 devices from public networks and restrict access to the management interface exclusively to trusted hosts through firewall or network segmentation.

Who is affected

Riello Netman 204 (firmware) in all versions up to and including 4.05.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Riello Ups Netman 204

    HW
    Riello-Ups
    all versions
  • Riello Ups Netman 204 Firmware

    OS
    Riello-Ups
    ≤ 4.05
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-47893CRITICAL10.0PL ✓same product

RCE w Riello-Ups NetMan 204 — upload webshella przez firmware

CVE-2017-6900CRITICAL9.8PL ✓same product

Riello NetMan 204 — command injection i bypass uwierzytelnienia

CVE-2022-47891HIGH8.1same product

All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the a...

CVE-2022-3372HIGH8.8same product

There is a CSRF vulnerability on Netman-204 version 02.05. An attacker could manage to change administrator pa...

CVE-2024-8877MEDIUM6.9same product

Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It ...