CVE-2019-15068
25.09.2019, 19:15
A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/reset administrators password without any authentication.Enginsight
Vendor | Product | Version |
---|---|---|
gigastone | smart_battery_a4_firmware | 𝑥 ≤ r1.7.9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-284 - Improper Access ControlThe software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
- CWE-306 - Missing Authentication for Critical FunctionThe product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.