Описание
The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station does not authenticate the station device, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information by reading cleartext packet data, related to the lack of SSL support.
Ссылки
- Third Party AdvisoryUS Government Resource
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:o:adcon:a840_telemetry_gateway_base_station_firmware:*:*:*:*:*:*:*:*
EPSS
Процентиль: 39%
0.00172
Низкий
8.7 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-20
Связанные уязвимости
CVSS3: 8.7
github
больше 3 лет назад
The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station does not authenticate the station device, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information by reading cleartext packet data, related to the lack of SSL support.
EPSS
Процентиль: 39%
0.00172
Низкий
8.7 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-20