PT-2022-3321 · Ws7200-10 · Ws7200-10
Linfeng Xiao
+2
·
Published
2022-06-28
·
Updated
2025-05-28
·
CVE-2022-33735
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WS7200-10 version 11.0.2.13
Description
The issue is related to a password verification vulnerability. It allows attackers on the LAN to use brute force cracking to obtain passwords, potentially disclosing sensitive system information. The vulnerability is associated with an incorrect implementation of the authentication algorithm, which can be exploited by a remote attacker to bypass existing security restrictions using a brute force attack.
Recommendations
For WS7200-10 version 11.0.2.13, as a temporary workaround, consider restricting access to the device or implementing additional security measures to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Restriction of Excessive Authentication Attempts
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ws7200-10