Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-40621

Опубликовано: 13 сент. 2022
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Because the WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 and earlier communicates over HTTP and not HTTPS, and because the hashing mechanism does not rely on a server-supplied key, it is possible for an attacker with sufficient network access to capture the hashed password of a logged on user and use it in a classic Pass-the-Hash style attack.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:wavlink:wn531g3_firmware:*:*:*:*:*:*:*:*
Версия до m31g3.v5030.200325 (включая)
cpe:2.3:h:wavlink:wn531g3:-:*:*:*:*:*:*:*

EPSS

Процентиль: 52%
0.00294
Низкий

7.5 High

CVSS3

Дефекты

CWE-294
CWE-294

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

Because the WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 and earlier communicates over HTTP and not HTTPS, and because the hashing mechanism does not rely on a server-supplied key, it is possible for an attacker with sufficient network access to capture the hashed password of a logged on user and use it in a classic Pass-the-Hash style attack.

EPSS

Процентиль: 52%
0.00294
Низкий

7.5 High

CVSS3

Дефекты

CWE-294
CWE-294