9.1

CVE-2024-31070

Initialization of a resource with an insecure default vulnerability in FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allows a remote unauthenticated attacker to access telnet service unlimitedly.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CenturysysFuturenet Nxr-610x Firmware Version < 21.14.11c
CenturysysFuturenet Nxr-g050 Firmware Version < 21.12.10
CenturysysFuturenet Nxr-g120 Firmware Version < 21.15.2c
CenturysysFuturenet Vxr-x64 Version < 21.7.32
CenturysysFuturenet Vxr-x86 Version < 10.1.5
CenturysysFuturenet Nxr-230/c Firmware Version < 5.30.13
   CenturysysFuturenet Nxr-230/c Version-
CenturysysFuturenet Nxr-350/c Firmware Version < 5.30.9c
   CenturysysFuturenet Nxr-350/c Version-
CenturysysFuturenet Nxr-530 Firmware Version < 21.11.14
   CenturysysFuturenet Nxr-530 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.07% 0.834
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CWE-1188 Initialization of a Resource with an Insecure Default

The product initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.