9.4

CVE-2017-9630

An Improper Authentication issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, LaserWash 360 and 360 Plus, all versions, LaserWash AutoXpress and AutoExpress Plus, all versions, LaserJet, all versions, ProTouch Tandem, all versions, ProTouch ICON, all versions, and ProTouch AutoGloss, all versions. The web server does not properly verify that provided authentication information is correct.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pdqinc ≫ Laserwash G5 Firmware Version -
   Pdqinc ≫ Laserwash G5 Version -
Pdqinc ≫ Laserwash G5 S Firmware Version -
   Pdqinc ≫ Laserwash G5 S Version -
Pdqinc ≫ Laserwash M5 Firmware Version -
   Pdqinc ≫ Laserwash M5 Version -
Pdqinc ≫ Laserwash 360 Firmware Version -
   Pdqinc ≫ Laserwash 360 Version -
Pdqinc ≫ Laserwash 360 Plus Firmware Version -
   Pdqinc ≫ Laserwash 360 Plus Version -
Pdqinc ≫ Laserjet Firmware Version -
   Pdqinc ≫ Laserjet Version -
Pdqinc ≫ Protouch Tandem Firmware Version -
   Pdqinc ≫ Protouch Tandem Version -
Pdqinc ≫ Protouch Icon Firmware Version -
   Pdqinc ≫ Protouch Icon Version -
Pdqinc ≫ Protouch Autogloss Firmware Version -
   Pdqinc ≫ Protouch Autogloss Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.19% 0.638
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.4 3.9 5.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://ics-cert.us-cert.gov/advisories/ICSA-17-208-03
Third Party Advisory
US Government Resource
Mitigation