Weak Authentication in Janitza UMG Devices Allows Brute-Force Attacks
CVE-2015-3972

Currently unrated

Key Information:

Vendor

Janitza

Status
Vendor
CVE Published:
28 October 2015

What is CVE-2015-3972?

The web interface of Janitza UMG devices (models 508, 509, 511, 604, and 605) is vulnerable due to its reliance on short PIN values for authentication. This limitation exposes the devices to remote attackers who can exploit this weakness via brute-force methods, potentially gaining unauthorized access.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.