Lucene search

K
cveCyberDanubeCVE-2024-8878
HistorySep 25, 2024 - 1:15 a.m.

CVE-2024-8878

2024-09-2501:15:47
CWE-640
CyberDanube
web.nvd.nist.gov
30
cve-2024-8878
password recovery
riello netman 204
unauthenticated
control takeover

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS4

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

39.6%

The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: through 4.05.

Affected configurations

Nvd
Node
riello-upsnetman_204_firmwareRange4.05
AND
riello-upsnetman_204Match-
VendorProductVersionCPE
riello-upsnetman_204_firmware*cpe:2.3:o:riello-ups:netman_204_firmware:*:*:*:*:*:*:*:*
riello-upsnetman_204-cpe:2.3:h:riello-ups:netman_204:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Netman 204",
    "vendor": "Riello",
    "versions": [
      {
        "lessThanOrEqual": "4.05",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS4

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

39.6%