CVE Vulnerabilities

CVE-2015-3972

Published: Oct 28, 2015 | Modified: Oct 28, 2015
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, which makes it easier for remote attackers to obtain access via a brute-force attack.

Affected Software

Name Vendor Start Version End Version
Umg_508 Janitza - (including) - (including)
Umg_509 Janitza - (including) - (including)
Umg_511 Janitza - (including) - (including)
Umg_604 Janitza - (including) - (including)
Umg_605 Janitza - (including) - (including)

References