InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy. This may allow an attacker with obtained user credentials to enumerate passwords and impersonate other application users and perform operations on their behalf.
References
Link | Resource |
---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-21-280-05 | Third Party Advisory US Government Resource |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: icscert
Published: 2021-10-07T00:00:00
Updated: 2021-10-19T12:10:32
Reserved: 2021-08-10T00:00:00
Link: CVE-2021-38462
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-10-19T13:15:10.833
Modified: 2021-10-22T15:06:37.917
Link: CVE-2021-38462
JSON object: View
Redhat Information
No data.
CWE