9.8
CVE-2022-23768
- EPSS 0.71%
- Veröffentlicht 19.09.2022 20:15:12
- Zuletzt bearbeitet 21.11.2024 06:49:14
- Quelle vuln@krcert.or.kr
- CVE-Watchlists
- Unerledigt
This Vulnerability in NIS-HAP11AC is caused by an exposed external port for the telnet service. Remote attackers use this vulnerability to induce all attacks such as source code hijacking, remote control of the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Neoinfosys ≫ Nis-hap11ac Firmware Version3.0 Updateb20201117095902
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.71% | 0.714 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| vuln@krcert.or.kr | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.