6.5
CVE-2022-40903
- EPSS 0.17%
- Veröffentlicht 14.11.2022 23:15:11
- Zuletzt bearbeitet 30.04.2025 19:15:50
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Aiphone GT-DMB-N 3-in-1 Video Entrance Station with NFC Reader 1.0.3 does not mitigate against repeated failed access attempts, which allows an attacker to gain administrative privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Aiphone ≫ Gt-dmb-n Firmware Version < 3.00
Aiphone ≫ Gt-dmb Firmware Version < 3.00
Aiphone ≫ Gt-dmb-lvn Firmware Version < 3.00
Aiphone ≫ Gt-db-vn Firmware Version < 2.00
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.388 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-307 Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.