CVE-2019-15068
EUVD-2019-614925.09.2019, 19:15
A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/reset administrator’s password without any authentication.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gigastone | smart_battery_a4_firmware | 𝑥 ≤ r1.7.9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-284 - Improper Access ControlThe software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
- CWE-306 - Missing Authentication for Critical FunctionThe product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.