Lucene search

K
nvd[email protected]NVD:CVE-2024-25735
HistoryMar 27, 2024 - 3:15 a.m.

CVE-2024-25735

2024-03-2703:15:12
CWE-284
web.nvd.nist.gov
3
wyrestorm
apollo vx20
remote attackers
cleartext passwords
softap
configuration request

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

6.6

Confidence

Low

EPSS

0.004

Percentile

73.6%

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

6.6

Confidence

Low

EPSS

0.004

Percentile

73.6%