CVE-2024-1039
01.02.2024, 22:15
Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device.Enginsight
Vendor | Product | Version |
---|---|---|
gesslergmbh | web-master_firmware | 7.9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-1391 - Use of Weak CredentialsThe product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.