← Back

CVE-2015-3972

nvd nist
Published: Oct 28, 2015Modified: May 6, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, which makes it easier for remote attackers to obtain access via a brute-force attack.

Affected (5)

5 products
Umg 508
Umg 509
Umg 511
Umg 604
Umg 605
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
All versions
All versions

Related CWEs

References (2)

Source: ics-cert@hq.dhs.gov
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource

Timeline

No history available yet.