7.5

CVE-2002-0628

The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for remote attackers to guess usernames and passwords via a brute force attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Polycom ≫ Viewstation 128 Version 6.5.1
Polycom ≫ Viewstation 128 Version 7.2
Polycom ≫ Viewstation 512 Version 6.5.1
Polycom ≫ Viewstation 512 Version 7.2
Polycom ≫ Viewstation Dcp Version 6.5.1
Polycom ≫ Viewstation Dcp Version 7.2
Polycom ≫ Viewstation Fx Vs4000 Version 4.1.5
Polycom ≫ Viewstation H.323 Version 6.5.1
Polycom ≫ Viewstation H.323 Version 7.2
Polycom ≫ Viewstation Mp Version 6.5.1
Polycom ≫ Viewstation Mp Version 7.2
Polycom ≫ Viewstation Sp 384 Version 6.5.1
Polycom ≫ Viewstation Sp 384 Version 7.2
Polycom ≫ Viewstation V.35 Version 6.5.1
Polycom ≫ Viewstation V.35 Version 7.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.19% 0.801
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-307 Improper Restriction of Excessive Authentication Attempts

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21089
Broken Link
http://www.ciac.org/ciac/bulletins/m-123.shtml
Patch
Vendor Advisory
Broken Link
http://www.polycom.com/common/pw_item_show_doc/0%2C%2C1444%2C00.pdf
Product
http://www.iss.net/security_center/static/9349.php
Vendor Advisory
Broken Link
http://www.securityfocus.com/bid/5635
Third Party Advisory
Vendor Advisory
Broken Link
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/44241
Third Party Advisory
VDB Entry