BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow the user to set a weak password because the strength is shown in configuration tool, but finally not enforced. This is usable and part of an attack chain to gain SSH root access.
References
Link Resource
https://psytester.github.io/CVE-2021-28914 Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-09-09T18:03:32

Updated: 2021-09-09T18:03:32

Reserved: 2021-03-19T00:00:00


Link: CVE-2021-28914

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-09-09T19:15:11.750

Modified: 2021-09-22T16:50:25.010


Link: CVE-2021-28914

JSON object: View

cve-icon Redhat Information

No data.

CWE