5.6
CVE-2016-4811
- EPSS 0.78%
- Veröffentlicht 19.06.2016 20:59:15
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Quelle vultures@jpcert.or.jp
- CVE-Watchlists
- Unerledigt
The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.15.1 and earlier for Android and 1.13.0 and earlier for iOS allows man-in-the-middle attackers to obtain API access via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ntt-bp ≫ Japan Connected-free Wi-fi Version1.13.0 SwPlatformiphone_os
Ntt-bp ≫ Japan Connected-free Wi-fi Version1.15.1 SwPlatformandroid
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.78% | 0.512 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.6 | 2.2 | 3.4 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
|
| nvd@nist.gov | 5.1 | 4.9 | 6.4 |
AV:N/AC:H/Au:N/C:P/I:P/A:P
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
https://play.google.com/store/apps/details?id=com.nttbp.jfw
http://jvn.jp/en/jp/JVN46888319/278948/index.html
http://jvn.jp/en/jp/JVN46888319/index.html
http://jvndb.jvn.jp/jvndb/JVNDB-2016-000076
https://itunes.apple.com/app/japan-connected-free-wi-fi/id810838196