CVE Vulnerabilities

CVE-2015-3972

Published: Oct 28, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, which makes it easier for remote attackers to obtain access via a brute-force attack.

Affected Software

NameVendorStart VersionEnd Version
Umg_508Janitza- (including)- (including)
Umg_509Janitza- (including)- (including)
Umg_511Janitza- (including)- (including)
Umg_604Janitza- (including)- (including)
Umg_605Janitza- (including)- (including)

References