CVE-2024-8887

CIRCUTOR Q-SMT in its firmware version 1.0.4, could be affected by a denial of service (DoS) attack if an attacker with access to the web service bypasses the authentication mechanisms on the login page, allowing the attacker to use all the functionalities implemented at web level that allow interacting with the device.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:circutor:q-smt_firmware:1.0.4:*:*:*:*:*:*:*
cpe:2.3:h:circutor:q-smt:-:*:*:*:*:*:*:*

History

01 Oct 2024, 17:30

Type Values Removed Values Added
References () https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-circutor-products - () https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-circutor-products - Third Party Advisory
CVSS v2 : unknown
v3 : 10.0
v2 : unknown
v3 : 8.6
CPE cpe:2.3:o:circutor:q-smt_firmware:1.0.4:*:*:*:*:*:*:*
cpe:2.3:h:circutor:q-smt:-:*:*:*:*:*:*:*
First Time Circutor
Circutor q-smt
Circutor q-smt Firmware

20 Sep 2024, 12:30

Type Values Removed Values Added
Summary
  • (es) CIRCUTOR Q-SMT en su versión de firmware 1.0.4, podría verse afectado por un ataque de denegación de servicio (DoS) si un atacante con acceso al servicio web evita los mecanismos de autenticación en la página de login, permitiendo al atacante utilizar todas las funcionalidades implementadas a nivel web que permiten interactuar con el dispositivo.

18 Sep 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-18 11:15

Updated : 2024-10-01 17:30


NVD link : CVE-2024-8887

Mitre link : CVE-2024-8887

CVE.ORG link : CVE-2024-8887


JSON object : View

Products Affected

circutor

  • q-smt
  • q-smt_firmware
CWE
CWE-1284

Improper Validation of Specified Quantity in Input