A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could
cause account takeover and unauthorized access to the system
when an attacker conducts brute-force attacks against the
equipment login. Note that the system supports only one concurrent session and implements a delay of more than a second
between failed login attempts making it difficult to automate the
attacks.
Metrics
Affected Vendors & Products
References
History
Tue, 26 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Hitachienergy
Hitachienergy nsd570 Firmware |
|
CPEs | cpe:2.3:o:hitachienergy:nsd570_firmware:*:*:*:*:*:*:*:* | |
Vendors & Products |
Hitachienergy
Hitachienergy nsd570 Firmware |
|
Metrics |
ssvc
|
Tue, 26 Nov 2024 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the equipment login. Note that the system supports only one concurrent session and implements a delay of more than a second between failed login attempts making it difficult to automate the attacks. | |
Weaknesses | CWE-307 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Hitachi Energy
Published: 2024-11-26T13:26:58.145Z
Updated: 2024-11-26T16:11:19.880Z
Reserved: 2024-10-14T11:03:53.306Z
Link: CVE-2024-9928
Vulnrichment
Updated: 2024-11-26T16:07:06.298Z
NVD
Status : Received
Published: 2024-11-26T14:15:22.777
Modified: 2024-11-26T14:15:22.777
Link: CVE-2024-9928
Redhat
No data.