Insecure Password Vulnerability in MOBOTIX S14 Devices
CVE-2019-7674
9.8CRITICAL
What is CVE-2019-7674?
An issue has been identified in MOBOTIX S14 MX-V4.2.1.61 devices where the /admin/access endpoint allows the setting of an insecure password, 'aaaaa', which may not meet security standards necessary for protecting sensitive user information. This flaw emphasizes the importance of implementing strong password policies to enhance device security in network environments.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved