5.3
CVE-2022-25215
- EPSS 0.39%
- Veröffentlicht 10.03.2022 17:47:01
- Zuletzt bearbeitet 21.11.2024 06:51:49
- Quelle vulnreport@tenable.com
- CVE-Watchlists
- Unerledigt
Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove) client MAC addresses to (or from) a list of banned hosts. Clients with those MAC addresses are then prevented from accessing either the WAN or the router itself.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phicomm ≫ K2 Firmware Version <= 22.5.9.163
Phicomm ≫ K3 Firmware Version <= 21.5.37.246
Phicomm ≫ K3c Firmware Version <= 32.1.15.93
Phicomm ≫ K2g Firmware Version <= 22.6.3.20
Phicomm ≫ K2p Firmware Version <= 20.4.1.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.39% | 0.57 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|