An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost.
The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.
Link | Tags |
---|---|
https://cert.vde.com/en/advisories/VDE-2024-068 | third party advisory |
https://cert.vde.com/en/advisories/VDE-2024-069 | third party advisory |
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-061.txt |