CVE-2015-3972
critical
CVSS v3
—
CVSS v2
10.0
VIR risk
10.0
Description
The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, which makes it easier for remote attackers to obtain access via a brute-force attack.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: ics-cert@hq.dhs.gov — https://ics-cert.us-cert.gov/advisories/ICSA-15-265-03
References
CWEs
CWE-254
Verify integrity in audit chain (admin only). AS-IS.