PT-2023-8053 · Eurotel · Eurotel Etl3100

Gjoko Krstic

·

Published

2023-04-29

·

Updated

2023-12-29

·

CVE-2023-6928

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions EuroTel ETL3100 versions v01c01 and v01x37
Description The issue is related to the lack of limitations on authentication attempts, which can be exploited by a remote attacker to gain full access to the system through brute-force guessing of administrative credentials.
Recommendations For EuroTel ETL3100 versions v01c01 and v01x37, consider implementing a workaround to limit the number of authentication attempts until a patch is available. As a temporary workaround, consider restricting access to the administrative interface to minimize the risk of exploitation. Avoid using remote password attacks on the affected system until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

BDU:2024-00030
CVE-2023-6928

Affected Products

Eurotel Etl3100