vendor:
NPM-V
by:
Saeed reza Zamanian
8,8
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: NPM-V
Affected Version From: 2.4.1
Affected Version To: 2.4.1
Patch Exists: NO
Related CWE: N/A
CPE: a:china-clever:npm-v
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
NPM-V(Network Power Manager) <= 2.4.1 Reset Password Vulnerability
An attacker can access to management console pages directly and without authentication. All files in these directories are directly accessible. An Attacker can directly access to the user page and Add User or View Password or Change Administrator credential without authentication.
Mitigation:
Ensure that authentication is properly implemented and enforced for all access to the device.