ZeroHour

CVE-2023-41926

CVSS 3.1
8.8 high
EPSS
<1%p18
Published
()
Modified
Description

The webserver utilizes basic authentication for its user login to the configuration interface. As encryption is disabled on port 80, it enables potential eavesdropping on user traffic, making it possible to intercept their credentials.

Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.