Home
HIGH: 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:LHIGH: 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:NDefault status
unaffected
All versions
affected
Description
User names used to access the web management interface are limited to the device identifier, which is a numerical identifier no more than 10 digits. A malicious actor can enumerate potential targets by incrementing or decrementing from known identifiers or through enumerating random digit sequences.
Problem types
Product status
All versions
Credits
Raúl Ignacio Cruz Jiménez reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-160-01
www.sinotrackgps.com/help-center