9.8
CVE-2019-7163
- EPSS 3.82%
- Veröffentlicht 02.08.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:47:41
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The web interface of Alcatel LINKZONE MW40-V-V1.0 MW40_LU_02.00_02 devices is vulnerable to an authentication bypass that allows an unauthenticated user to have access to the web interface without knowing the administrator's password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tcl ≫ Alcatel Linkzone Firmware Versionmw40-v-v1.0_mw40_lu_02.00_02
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.82% | 0.877 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.