Show plain JSON{"id": "CVE-2023-0750", "metrics": {"cvssMetricV31": [{"type": "Secondary", "source": "vulnerability@ncsc.ch", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}, {"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}]}, "published": "2023-04-06T14:15:07.913", "references": [{"url": "https://support.lynx-technik.com/support/solutions/articles/1000317081-pec-1864-web-ui-for-configuration", "tags": ["Vendor Advisory"], "source": "vulnerability@ncsc.ch"}, {"url": "https://support.lynx-technik.com/support/solutions/articles/1000317081-pec-1864-web-ui-for-configuration", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Secondary", "source": "vulnerability@ncsc.ch", "description": [{"lang": "en", "value": "CWE-602"}]}, {"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-311"}]}], "descriptions": [{"lang": "en", "value": "Yellobrik PEC-1864 implements authentication checks via javascript in the frontend interface.\u00a0 When the device can be accessed over the network an attacker could bypass authentication.\n\n\n\n\nThis would allow an attacker to : \n- Change the password, resulting in a DOS of the users\n\n- Change the streaming source, compromising the integrity of the stream\n\n- Change the streaming destination, compromising the confidentiality of the stream\n\n\n\n\n\n\n\n\nThis issue affects Yellowbrik: PEC 1864. No patch has been issued by the manufacturer as this model was discontinued.\n\n\n\n\n\n\n\n\n\n\n\n\n"}], "lastModified": "2024-11-21T07:37:45.130", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:lynx-technik:yellobrik_pec_1864_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "77D15174-B673-4FC9-A6A1-3AFCF7887840"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:lynx-technik:yellobrik_pec_1864:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "3DE5B4F1-4DFB-4FD3-92D5-43152E93ACAD"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "vulnerability@ncsc.ch"}