CVE-2024-8878
Severity CVSS v4.0:
Pending analysis
Type:
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
Publication date:
25/09/2024
Last modified:
30/09/2024
Description
The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: through 4.05.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:riello-ups:netman_204_firmware:*:*:*:*:*:*:*:* | 4.05 (including) | |
cpe:2.3:h:riello-ups:netman_204:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page