PT-2024-10738 · Alecto · Alecto Ivm-100

Jasper Nota

+2

·

Published

2024-11-07

·

Updated

2024-11-10

·

CVE-2019-20462

CVSS v3.1

5.3

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Alecto IVM-100 version 2019-11-12
Description An issue was discovered where a large amount of information is disclosed when attaching to the serial interface at the board level and rebooting the device. This includes the view password and the password of the Wi-Fi access point that the device used.
Recommendations For Alecto IVM-100 version 2019-11-12, as a temporary workaround, consider restricting access to the serial interface at the board level until a patch is available. However, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2019-20462

Affected Products

Alecto Ivm-100