5.9
CVE-2018-16546
- EPSS 0.34%
- Veröffentlicht 05.09.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:56
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Amcrest networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation, as demonstrated by Amcrest_IPC-HX1X3X-LEXUS_Eng_N_AMCREST_V2.420.AC01.3.R.20180206.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Amcrest ≫ Amcrest Ipc-hx1x3x-lexus Eng N Amcrest Versionv2.420.ac01.3.r.20180206
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.34% | 0.537 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.