8.8

CVE-2021-36799

KNX ETS5 through 5.7.6 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
KnxEngineering Tool Software 5 Version <= 5.7.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.332
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

http://packetstormsecurity.com/files/165200/ETS5-Password-Recovery-Tool.html
Third Party Advisory
VDB Entry
https://github.com/robertguetzkow/ets5-password-recovery
Third Party Advisory
https://www.knx.org/knx-en/for-professionals/software/ets-5-professional/
Vendor Advisory
Product