7.5

CVE-2002-0628

The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for remote attackers to guess usernames and passwords via a brute force attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PolycomViewstation 128 Version6.5.1
PolycomViewstation 128 Version7.2
PolycomViewstation 512 Version6.5.1
PolycomViewstation 512 Version7.2
PolycomViewstation Dcp Version6.5.1
PolycomViewstation Dcp Version7.2
PolycomViewstation Fx Vs4000 Version4.1.5
PolycomViewstation H.323 Version6.5.1
PolycomViewstation H.323 Version7.2
PolycomViewstation Mp Version6.5.1
PolycomViewstation Mp Version7.2
PolycomViewstation Sp 384 Version6.5.1
PolycomViewstation Sp 384 Version7.2
PolycomViewstation V.35 Version6.5.1
PolycomViewstation V.35 Version7.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.71% 0.818
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-307 Improper Restriction of Excessive Authentication Attempts

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.