10
CVE-2019-15497
- EPSS 1.54%
- Published 26.08.2019 21:15:11
- Last modified 21.11.2024 04:28:52
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP.
Data is provided by the National Vulnerability Database (NVD)
Blackbox ≫ Icompel Firmware Version >= 9.2.3 <= 11.1.4
Onelan ≫ Net-top-box Firmware Version >= 9.2.3 <= 11.1.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.54% | 0.796 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.