9.8
CVE-2025-0456
- EPSS 1.15%
- Veröffentlicht 16.01.2025 02:15:27
- Zuletzt bearbeitet 16.01.2025 02:15:27
- Quelle twcert@cert.org.tw
- CVE-Watchlists
- Unerledigt
The airPASS from NetVision Information has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access the specific administrative functionality to retrieve * all accounts and passwords.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerNetVision Information
≫
Produkt
airPASS
Default Statusunaffected
Version <
2.9.0.241231
Version
2.9.0
Status
affected
Version <
3.0.0.241231
Version
3.0.0
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.15% | 0.782 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| twcert@cert.org.tw | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.