Vulnerabilities > CVE-2015-3972 - 7PK - Security Features vulnerability in Janitza products

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
janitza
CWE-254
critical

Summary

The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, which makes it easier for remote attackers to obtain access via a brute-force attack.

Vulnerable Configurations

Part Description Count
Hardware
Janitza
5

Common Weakness Enumeration (CWE)