4.3
CVE-2022-0184
- EPSS 0.07%
- Veröffentlicht 17.01.2022 10:15:08
- Zuletzt bearbeitet 21.11.2024 06:38:05
- Quelle vultures@jpcert.or.jp
- CVE-Watchlists
- Unerledigt
Insufficiently protected credentials vulnerability in 'TEPRA' PRO SR5900P Ver.1.080 and earlier and 'TEPRA' PRO SR-R7900P Ver.1.030 and earlier allows an attacker on the adjacent network to obtain credentials for connecting to the Wi-Fi access point with the infrastructure mode.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kingjim ≫ Tepura Pro Sr5900p Firmware Version <= 1.080
Kingjim ≫ Tepura Pro Sr-7900p Firmware Version <= 1.030
Kingjim ≫ Spc10 Firmware Version <= 1.0.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.186 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| nvd@nist.gov | 3.3 | 6.5 | 2.9 |
AV:A/AC:L/Au:N/C:P/I:N/A:N
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.