PT-2024-13015 · Kiloview · P1/P2+2

Published

2024-07-02

·

Updated

2024-07-02

·

CVE-2023-41926

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software or versions mentioned
Description The issue concerns the use of basic authentication for user login to the configuration interface of a webserver. Since encryption is disabled on port 80, this setup allows potential eavesdropping on user traffic, making it possible for attackers to intercept user credentials.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2023-41926

Affected Products

P1/P2
P1 4G Video Encoder Firmware
P2 4G Video Encoder Firmware