Vulnerabilities > CVE-2015-2915 - Credentials Management vulnerability in Securifi Almond-2015 Firmware and Almond Firmware

047910
CVSS 7.3 - HIGH
Attack vector
ADJACENT_NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
COMPLETE
low complexity
securifi
CWE-255

Summary

Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M have a default password of admin for the admin account, which allows remote attackers to obtain web-management access by leveraging the ability to authenticate from the intranet.

Vulnerable Configurations

Part Description Count
OS
Securifi
2
Hardware
Securifi
2

Common Weakness Enumeration (CWE)