10
CVE-2019-9533
- EPSS 1.51%
- Veröffentlicht 10.10.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:51:48
- Quelle cret@cert.org
- CVE-Watchlists
- Unerledigt
The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08
The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08. This could allow an attacker to reverse-engineer the password from available versions to gain authenticated access to the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cobham ≫ Explorer 710 Firmware Version1.07
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.51% | 0.711 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
https://kb.cert.org/vuls/id/719689/