9.8
CVE-2019-17215
- EPSS 0.31%
- Veröffentlicht 06.10.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:31:52
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no bruteforce protection (e.g., lockout) established. An attacker might be able to bruteforce the password to authenticate on the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Vzug ≫ Combi-stream Mslq Firmware Version < ethernet_r07
Vzug ≫ Combi-stream Mslq Firmware Version < wlan_r05
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.537 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-307 Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.