8.8
CVE-2023-0896
- EPSS 0.09%
- Veröffentlicht 01.05.2023 14:15:09
- Zuletzt bearbeitet 21.11.2024 07:38:03
- Quelle psirt@lenovo.com
- Teams Watchlist Login
- Unerledigt Login
A default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device access to an attacker with local network access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lenovo ≫ Smart Clock Essential With Alexa Built In Firmware Version < 90
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.09% | 0.237 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
psirt@lenovo.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.