Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-25309

Опубликовано: 02 мар. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 5
EPSS Низкий

Описание

The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password policy that forces a 4-digit password) allows remote attackers to easily obtain administrative access via brute-force attacks.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:gigaset:dx600a_firmware:v41.00-175:*:*:*:*:*:*:*
cpe:2.3:h:gigaset:dx600a:-:*:*:*:*:*:*:*

EPSS

Процентиль: 68%
0.00556
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password policy that forces a 4-digit password) allows remote attackers to easily obtain administrative access via brute-force attacks.

EPSS

Процентиль: 68%
0.00556
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-307