Lucene search

K
cve[email protected]CVE-2015-3971
HistoryOct 28, 2015 - 10:59 a.m.

CVE-2015-3971

2015-10-2810:59:05
CWE-284
web.nvd.nist.gov
41
cve-2015-3971
janitza umg
unauthenticated access
remote code execution
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

75.2%

The debug interface on Janitza UMG 508, 509, 511, 604, and 605 devices does not require authentication, which allows remote attackers to read or write to files, or execute arbitrary JASIC code, via a session on TCP port 1239.

Affected configurations

NVD
Node
janitzaumg_508Match-
OR
janitzaumg_509Match-
OR
janitzaumg_511Match-
OR
janitzaumg_604Match-
OR
janitzaumg_605Match-

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

75.2%

Related for CVE-2015-3971