Insecure Password Vulnerability in MOBOTIX S14 Devices
CVE-2019-7674

9.8CRITICAL

Key Information:

Vendor

Mobotix

Vendor
CVE Published:
9 February 2019

What is CVE-2019-7674?

An issue has been identified in MOBOTIX S14 MX-V4.2.1.61 devices where the /admin/access endpoint allows the setting of an insecure password, 'aaaaa', which may not meet security standards necessary for protecting sensitive user information. This flaw emphasizes the importance of implementing strong password policies to enhance device security in network environments.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.