9.8

CVE-2024-5404

ifm: moneo prone to weak password recovery mechanism

An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak password recovery mechanism.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellerifm
Produkt moneo_qha210
Default Statusunknown
Version <= 1.13
Version 0
Status affected
Herstellerifm
Produkt moneo_qha300
Default Statusunknown
Version <= 1.13
Version 0
Status affected
Herstellerifm
Produkt moneo_qva200
Default Statusunknown
Version <= 1.13
Version 0
Status affected
Herstellerifm
Produkt moneo_for_microsoft_windows
Default Statusunknown
Version <= 1.13
Version 0
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.55% 0.416
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
info@cert.vde.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-640 Weak Password Recovery Mechanism for Forgotten Password

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.