7.5

CVE-2002-0628

The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for remote attackers to guess usernames and passwords via a brute force attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PolycomViewstation 128 Version6.5.1
PolycomViewstation 128 Version7.2
PolycomViewstation 512 Version6.5.1
PolycomViewstation 512 Version7.2
PolycomViewstation Dcp Version6.5.1
PolycomViewstation Dcp Version7.2
PolycomViewstation Fx Vs4000 Version4.1.5
PolycomViewstation H.323 Version6.5.1
PolycomViewstation H.323 Version7.2
PolycomViewstation Mp Version6.5.1
PolycomViewstation Mp Version7.2
PolycomViewstation Sp 384 Version6.5.1
PolycomViewstation Sp 384 Version7.2
PolycomViewstation V.35 Version6.5.1
PolycomViewstation V.35 Version7.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.19% 0.801
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-307 Improper Restriction of Excessive Authentication Attempts

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21089
Broken Link
http://www.ciac.org/ciac/bulletins/m-123.shtml
Patch
Vendor Advisory
Broken Link
http://www.polycom.com/common/pw_item_show_doc/0%2C%2C1444%2C00.pdf
Product
http://www.iss.net/security_center/static/9349.php
Vendor Advisory
Broken Link
http://www.securityfocus.com/bid/5635
Third Party Advisory
Vendor Advisory
Broken Link
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/44241
Third Party Advisory
VDB Entry