Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qp56-x698-cr67

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) generates the password for the fwupgrade account by performing a calculation on the MAC address, which makes it easier for remote attackers to obtain access via a (1) ARP request message or (2) Neighbor Solicitation message.

The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) generates the password for the fwupgrade account by performing a calculation on the MAC address, which makes it easier for remote attackers to obtain access via a (1) ARP request message or (2) Neighbor Solicitation message.

EPSS

Процентиль: 82%
0.01629
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
около 14 лет назад

The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) generates the password for the fwupgrade account by performing a calculation on the MAC address, which makes it easier for remote attackers to obtain access via a (1) ARP request message or (2) Neighbor Solicitation message.

EPSS

Процентиль: 82%
0.01629
Низкий

Дефекты

CWE-287