Lucene search

K
cveJciCVE-2023-3548
HistoryJul 25, 2023 - 2:15 p.m.

CVE-2023-3548

2023-07-2514:15:11
CWE-307
jci
web.nvd.nist.gov
17
unauthorized access
iq wifi 6
cve-2023-3548
brute force authentication

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.002

Percentile

56.7%

An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.

Affected configurations

Nvd
Node
johnsoncontrolsiq_wifi_6_firmwareRange<2.0.2
AND
johnsoncontrolsiq_wifi_6Match-
VendorProductVersionCPE
johnsoncontrolsiq_wifi_6_firmware*cpe:2.3:o:johnsoncontrols:iq_wifi_6_firmware:*:*:*:*:*:*:*:*
johnsoncontrolsiq_wifi_6-cpe:2.3:h:johnsoncontrols:iq_wifi_6:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "IQ Wifi 6",
    "vendor": "Johnson Controls",
    "versions": [
      {
        "lessThan": "2.0.2",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.002

Percentile

56.7%

Related for CVE-2023-3548