9.8
CVE-2023-6928
- EPSS 0.08%
- Veröffentlicht 19.12.2023 23:15:08
- Zuletzt bearbeitet 21.11.2024 08:44:51
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
EuroTel ETL3100 versions v01c01 and v01x37 does not limit the number of attempts to guess administrative credentials in remote password attacks to gain full control of the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eurotel ≫ Etl3100 Firmware Version01c01
Eurotel ≫ Etl3100 Firmware Version01x37
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.244 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| ics-cert@hq.dhs.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-307 Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.