CVE-2022-40903

Aiphone GT-DMB-N 3-in-1 Video Entrance Station with NFC Reader 1.0.3 does not mitigate against repeated failed access attempts, which allows an attacker to gain administrative privileges.
References
Link Resource
https://jvn.jp/en/jp/JVN75437943/index.html Third Party Advisory VDB Entry
https://www.aiphone.net/ Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:aiphone:gt-dmb-n_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:aiphone:gt-dmb-n:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:aiphone:gt-dmb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:aiphone:gt-dmb:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:aiphone:gt-dmb-lvn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:aiphone:gt-dmb-lvn:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:aiphone:gt-db-vn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:aiphone:gt-db-vn:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-11-14 23:15

Updated : 2024-02-28 19:29


NVD link : CVE-2022-40903

Mitre link : CVE-2022-40903

CVE.ORG link : CVE-2022-40903


JSON object : View

Products Affected

aiphone

  • gt-dmb
  • gt-dmb_firmware
  • gt-db-vn_firmware
  • gt-dmb-n
  • gt-dmb-n_firmware
  • gt-dmb-lvn
  • gt-dmb-lvn_firmware
  • gt-db-vn