Lucene search

K
nvd[email protected]NVD:CVE-2024-28744
HistoryApr 08, 2024 - 1:15 a.m.

CVE-2024-28744

2024-04-0801:15:56
web.nvd.nist.gov
cve-2024-28744
empty password
authentication bypass
non ms mode
network configuration
user information

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.1%

The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earlier. An unauthenticated attacker may log in to the product with no password, and obtain and/or alter information such as network configuration and user information. The products are affected only when running in non MS mode with the initial configuration.

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.1%

Related for NVD:CVE-2024-28744