7.8

CVE-2007-2649

Deutsche Telekom (T-com) Speedport W 700v uses JavaScript delays for invalid authentication attempts to the CGI script, which allows remote attackers to bypass the delays and conduct brute-force attacks via direct calls to the authentication CGI script.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.94% 0.775
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:C/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://osvdb.org/36011
http://secunia.com/advisories/25266
Vendor Advisory
http://securityreason.com/securityalert/2705
http://www.devtarget.org/speedport700-advisory-05-2007.txt
Vendor Advisory
http://www.securityfocus.com/archive/1/468361/100/0/threaded
http://www.securityfocus.com/bid/23967
https://exchange.xforce.ibmcloud.com/vulnerabilities/34334