CVE-2023-24502
6.5
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
Electra Central AC unit – The unit opens an AP with an easily calculated password.
Affected (4)
Products: Electra Air: Central Ac Unit Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version v4 |
| Running on/with | Platform Versions |
|---|---|
Electra Air Central Ac Unit | All versions |
Related CWEs
CWE-326
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CWE-521
Weak Password Requirements
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.