7.5
CVE-2023-24502
- EPSS 0.02%
- Veröffentlicht 17.04.2023 22:15:08
- Zuletzt bearbeitet 06.02.2025 16:15:33
- Quelle cna@cyber.gov.il
- CVE-Watchlists
- Unerledigt
Electra Central AC unit – The unit opens an AP with an easily calculated password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Electra-air ≫ Central Ac Unit Firmware Versionv4
Electra-air ≫ Central Ac Unit Firmware Versionv5
Electra-air ≫ Central Ac Unit Firmware Versionv7
Electra-air ≫ Central Ac Unit Firmware Versionv8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.058 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| cna@cyber.gov.il | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-326 Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CWE-521 Weak Password Requirements
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.