CVE-2024-8878

The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: through 4.05.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:riello-ups:netman_204_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:riello-ups:netman_204:-:*:*:*:*:*:*:*

History

30 Sep 2024, 15:21

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:o:riello-ups:netman_204_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:riello-ups:netman_204:-:*:*:*:*:*:*:*
First Time Riello-ups
Riello-ups netman 204
Riello-ups netman 204 Firmware
References () https://cyberdanube.com/en/en-multiple-vulnerabilities-in-riello-netman-204/index.html - () https://cyberdanube.com/en/en-multiple-vulnerabilities-in-riello-netman-204/index.html - Vendor Advisory

26 Sep 2024, 13:32

Type Values Removed Values Added
Summary
  • (es) El mecanismo de recuperación de contraseña para la contraseña olvidada en Riello Netman 204 permite a un atacante restablecer la contraseña de administrador y tomar el control del dispositivo. Este problema afecta a Netman 204: hasta la versión 4.05.

25 Sep 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-25 01:15

Updated : 2024-09-30 15:21


NVD link : CVE-2024-8878

Mitre link : CVE-2024-8878

CVE.ORG link : CVE-2024-8878


JSON object : View

Products Affected

riello-ups

  • netman_204
  • netman_204_firmware
CWE
CWE-640

Weak Password Recovery Mechanism for Forgotten Password