CVE-2020-35586
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/12/2020
Last modified:
23/12/2020
Description
In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requirement (e.g., it might be all digits or all lowercase letters).
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:mersive:solstice_pod_firmware:*:*:*:*:*:*:*:* | 3.0.3 (excluding) | |
| cpe:2.3:h:mersive:solstice_pod:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



