Vulnerabilities > Plummac

DATE CVE VULNERABILITY TITLE RISK
2020-12-08 CVE-2020-28946 Missing Authentication for Critical Function vulnerability in Plummac Ik-401 Firmware
An improper webserver configuration on Plum IK-401 devices with firmware before 1.02 allows an attacker (with network access to the device) to obtain the configuration file, including hashed credential data.
network
low complexity
plummac CWE-306
7.5