← Back

CVE-2021-38474

nvd nist
Published: Oct 19, 2021Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have has no account lockout policy configured for the login page of the product. This may allow an attacker to execute a brute-force password attack with no time limitation and without harming the normal operation of the user. This could allow an attacker to gain valid credentials for the product interface.

Affected (2)

Ir615 Firmware
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.3.0.r4724
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.3.0.r4870
Running on/withPlatform Versions
Inhandnetworks
Ir615
All versions

References (2)

Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.