4.3

CVE-2023-45194

Use of default credentials vulnerability in MR-GM2 firmware Ver. 3.00.03 and earlier, and MR-GM3 (-D/-K/-S/-DK/-DKS/-M/-W) firmware Ver. 1.03.45 and earlier allows a network-adjacent unauthenticated attacker to intercept wireless LAN communication, when the affected product performs the communication without changing the pre-shared key from the factory-default configuration.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MrlMr-gm3-d Firmware Version < 1.04.00
   MrlMr-gm3-d Version-
MrlMr-gm3-k Firmware Version < 1.04.00
   MrlMr-gm3-k Version-
MrlMr-gm3-s Firmware Version < 1.04.00
   MrlMr-gm3-s Version-
MrlMr-gm3-dks Firmware Version < 1.04.00
   MrlMr-gm3-dks Version-
MrlMr-gm3-m Firmware Version < 1.04.00
   MrlMr-gm3-m Version-
MrlMr-gm2 Firmware Version < 3.01.00
   MrlMr-gm2 Version-
MrlMr-gm3-w Firmware Version < 1.04.00
   MrlMr-gm3-w Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.07% 0.215
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.