10
CVE-2015-2909
- EPSS 3.57%
- Veröffentlicht 06.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 02:28:18
- Quelle cret@cert.org
- CVE-Watchlists
- Unerledigt
Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the administrator configures login credentials, which makes it easier for remote attackers to obtain access by leveraging situations in which this warning was not heeded. NOTE: the vendor states "The user is presented with clear warnings on the GUI that they should set usernames and passwords."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netvu ≫ Dv-ip Express Firmware Version-
Netvu ≫ Sd-advanced - Sdhd Firmware Version-
Netvu ≫ Sd-advanced 8/12/16 Vga Firmware Version-
Netvu ≫ Sd Advanced Closed Iptv (m3u) Firmware Version-
Netvu ≫ Sd Advanced Non Closed Iptv (m3u) Firmware Version-
Netvu ≫ Sd Advanced Nvr Firmware Version-
Netvu ≫ Sd 32 (m3g) Firmware Version-
Netvu ≫ Sd 32 (m3h) Firmware Version-
Netvu ≫ Sd 4 (m3s) Firmware Version-
Netvu ≫ Sd 4 (m3t) Firmware Version-
Netvu ≫ Sd 8/12/16 No Kbd (m3r) Firmware Version-
Netvu ≫ Sd 8/12/16 No Kbd (m3s) Firmware Version-
Netvu ≫ Sd 8/16 Front Panel Kbd (m3r) Firmware Version-
Netvu ≫ Sd 8/16 Front Panel Kbd (m3u) Firmware Version-
Netvu ≫ Ecosense 4/8/16 (m4t) Firmware Version-
Netvu ≫ Ds2 (dvtr) Firmware Version-
Netvu ≫ Ds2 (dvtu) Firmware Version-
Netvu ≫ Ds2 (dvtx) Firmware Version-
Netvu ≫ Ds2 (dvtx) Netvu Connected Firmware Version-
Netvu ≫ Ds2 (m2ip) Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.57% | 0.866 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.