9.8
CVE-2023-36669
- EPSS 0.22%
- Veröffentlicht 18.07.2023 18:15:12
- Zuletzt bearbeitet 21.11.2024 08:10:17
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Missing Authentication for a Critical Function within the Kratos NGC Indoor Unit (IDU) before 11.4 allows remote attackers to obtain arbitrary control of the IDU/ODU system. Any attacker with layer-3 network access to the IDU can impersonate the Touch Panel Unit (TPU) within the IDU by sending crafted TCP requests to the IDU.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kratosdefense ≫ Ngc Indoor Unit Firmware Version < 11.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.441 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.