5.6

CVE-2016-4811

The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.15.1 and earlier for Android and 1.13.0 and earlier for iOS allows man-in-the-middle attackers to obtain API access via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ntt-bpJapan Connected-free Wi-fi Version1.13.0 SwPlatformiphone_os
Ntt-bpJapan Connected-free Wi-fi Version1.15.1 SwPlatformandroid
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.78% 0.512
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.6 2.2 3.4
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://play.google.com/store/apps/details?id=com.nttbp.jfw
http://jvn.jp/en/jp/JVN46888319/278948/index.html
Vendor Advisory
http://jvn.jp/en/jp/JVN46888319/index.html
Vendor Advisory
http://jvndb.jvn.jp/jvndb/JVNDB-2016-000076
Vendor Advisory
https://itunes.apple.com/app/japan-connected-free-wi-fi/id810838196