CIRCUTOR Q-SMT in its firmware version 1.0.4, could be affected by a denial of service (DoS) attack if an attacker with access to the web service bypasses the authentication mechanisms on the login page, allowing the attacker to use all the functionalities implemented at web level that allow interacting with the device.
History

Tue, 01 Oct 2024 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Circutor q-smt
Circutor q-smt Firmware
CPEs cpe:2.3:h:circutor:q-smt:-:*:*:*:*:*:*:*
cpe:2.3:o:circutor:q-smt_firmware:1.0.4:*:*:*:*:*:*:*
Vendors & Products Circutor q-smt
Circutor q-smt Firmware

Wed, 18 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Circutor
Circutor circutor Q Smt
CPEs cpe:2.3:a:circutor:circutor_q_smt:*:*:*:*:*:*:*:*
Vendors & Products Circutor
Circutor circutor Q Smt
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 18 Sep 2024 11:15:00 +0000

Type Values Removed Values Added
Description CIRCUTOR Q-SMT in its firmware version 1.0.4, could be affected by a denial of service (DoS) attack if an attacker with access to the web service bypasses the authentication mechanisms on the login page, allowing the attacker to use all the functionalities implemented at web level that allow interacting with the device.
Title Authentication bypass vulnerability on CIRCUTOR Q-SMT
Weaknesses CWE-1284
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2024-09-18T11:05:31.015Z

Updated: 2024-09-18T13:26:55.753Z

Reserved: 2024-09-16T10:20:28.952Z

Link: CVE-2024-8887

cve-icon Vulnrichment

Updated: 2024-09-18T13:26:47.790Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-18T11:15:10.530

Modified: 2024-10-01T17:30:07.597

Link: CVE-2024-8887

cve-icon Redhat

No data.