Vulnerabilities > Lannerinc

DATE CVE VULNERABILITY TITLE RISK
2022-10-24 CVE-2021-45925 Information Exposure Through Discrepancy vulnerability in Lannerinc Iac-Ast2500A Firmware 1.10.0
Observable discrepancies in the login process allow an attacker to guess legitimate user names registered in the BMC.
network
low complexity
lannerinc CWE-203
5.3
2022-10-24 CVE-2021-46279 Session Fixation vulnerability in Lannerinc Iac-Ast2500A Firmware 1.10.0
Session fixation and insufficient session expiration vulnerabilities allow an attacker to perfom session hijacking attacks against users.
network
low complexity
lannerinc CWE-384
8.8
2022-10-24 CVE-2021-4228 Use of Hard-coded Credentials vulnerability in Lannerinc Iac-Ast2500 Firmware 1.00.0
Use of hard-coded TLS certificate by default allows an attacker to perform Man-in-the-Middle (MitM) attacks even in the presence of the HTTPS connection.
network
high complexity
lannerinc CWE-798
7.4