6.5
CVE-2022-40903
- EPSS 0.11%
- Published 14.11.2022 23:15:11
- Last modified 30.04.2025 19:15:50
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Aiphone GT-DMB-N 3-in-1 Video Entrance Station with NFC Reader 1.0.3 does not mitigate against repeated failed access attempts, which allows an attacker to gain administrative privileges.
Data is provided by the National Vulnerability Database (NVD)
Aiphone ≫ Gt-dmb-n Firmware Version < 3.00
Aiphone ≫ Gt-dmb Firmware Version < 3.00
Aiphone ≫ Gt-dmb-lvn Firmware Version < 3.00
Aiphone ≫ Gt-db-vn Firmware Version < 2.00
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.11% | 0.303 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-307 Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.