ZeroHour

CVE-2024-25734

PoC
CVSS 3.1
7.5 high
EPSS
4%p90
Published
()
Modified
Description

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is entered, which might make it easier for remote attackers to enumerate user accounts.

Vendors
wyrestorm
Products
apollo vx20 firmware
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.