CVE-2015-7285
25.11.2015, 04:59
CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 do not require authentication from Alarm Receiving Center (ARC) servers, which allows man-in-the-middle attackers to bypass intended access restrictions via a spoofed HSxx response.Enginsight
Vendor | Product | Version |
---|---|---|
csl_dualcom | gprs_cs2300-r_firmware | 1.25 |
csl_dualcom | gprs_cs2300-r_firmware | 3.53 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration