Lucene search

K
nvd[email protected]NVD:CVE-2024-8878
HistorySep 25, 2024 - 1:15 a.m.

CVE-2024-8878

2024-09-2501:15:47
CWE-640
web.nvd.nist.gov
4
password recovery mechanism
forgotten password
riello netman 204
admin password
device control
netman 204
version 4.05
cve-2024-8878

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

39.6%

The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: through 4.05.

Affected configurations

Nvd
Node
riello-upsnetman_204_firmwareRange4.05
AND
riello-upsnetman_204Match-
VendorProductVersionCPE
riello-upsnetman_204_firmware*cpe:2.3:o:riello-ups:netman_204_firmware:*:*:*:*:*:*:*:*
riello-upsnetman_204-cpe:2.3:h:riello-ups:netman_204:-:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

39.6%

Related for NVD:CVE-2024-8878