CVE-2024-27168
7.1
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Exploitability: 2.5 / Impact: 4.0
Source: ecc0f906-8666-484c-bcf8-c3b7520a72f0 (Secondary)
Description
It appears that some hardcoded keys are used for authentication to internal API. Knowing these private keys may allow attackers to bypass authentication and reach administrative interfaces. As for the affected products/models/versions, see the reference URL.
References (8)
Source: ecc0f906-8666-484c-bcf8-c3b7520a72f0
Source: ecc0f906-8666-484c-bcf8-c3b7520a72f0
Source: ecc0f906-8666-484c-bcf8-c3b7520a72f0
Source: ecc0f906-8666-484c-bcf8-c3b7520a72f0
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.