10
CVE-2019-15497
- EPSS 1.54%
- Veröffentlicht 26.08.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:28:52
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Blackbox ≫ Icompel Firmware Version >= 9.2.3 <= 11.1.4
Onelan ≫ Net-top-box Firmware Version >= 9.2.3 <= 11.1.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.54% | 0.796 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.