6.5
CVE-2020-7492
- EPSS 0.29%
- Veröffentlicht 16.06.2020 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:37:15
- Quelle cybersecurity@se.com
- Teams Watchlist Login
- Unerledigt Login
A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the discovery of the password when the user is entering the password because it is not masqueraded.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electric ≫ Gp-pro Ex Firmware Version >= 1.00 <= 4.09.120
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.29% | 0.495 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-521 Weak Password Requirements
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.