7.5
CVE-2018-20220
- EPSS 43.6%
- Veröffentlicht 21.03.2019 16:00:35
- Zuletzt bearbeitet 21.11.2024 04:01:06
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authentication before it can be interacted with, a large portion of the HTTP endpoints are missing authentication. An attacker is able to view these pages before being authenticated, and some of these pages may disclose sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Teracue ≫ Enc-400 Hdmi Firmware Version <= 2.56
Teracue ≫ Enc-400 Hdmi2 Firmware Version <= 2.56
Teracue ≫ Enc-400 Hdsdi Firmware Version <= 2.56
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 43.6% | 0.974 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.