Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-3774

Опубликовано: 05 нояб. 2021
Источник: nvd
CVSS3: 7.4
CVSS3: 6.5
CVSS2: 4.3
EPSS Низкий

Описание

Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security measures in its initial setup. This could allow a remote attacker to obtain the Wi-Fi SSID as well as the password configured by the user from Meross app via Http/JSON plain request.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:meross:mss550x_firmware:*:*:*:*:*:*:*:*
Версия до 3.1.3 (включая)
cpe:2.3:h:meross:mss550x:-:*:*:*:*:*:*:*

EPSS

Процентиль: 36%
0.00151
Низкий

7.4 High

CVSS3

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-319
CWE-319

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security measures in its initial setup. This could allow a remote attacker to obtain the Wi-Fi SSID as well as the password configured by the user from Meross app via Http/JSON plain request.

EPSS

Процентиль: 36%
0.00151
Низкий

7.4 High

CVSS3

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-319
CWE-319