| ID |
CVE-2021-28372
|
| Sažetak |
ThroughTek's Kalay Platform 2.0 network allows an attacker to impersonate an arbitrary ThroughTek (TUTK) device given a valid 20-byte uniquely assigned identifier (UID). This could result in an attacker hijacking a victim's connection and forcing them into supplying credentials needed to access the victim TUTK device. |
| Reference |
|
| CVSS |
| Base: | 7.6 |
| Impact: | 10.0 |
| Exploitability: | 4.9 |
|
| Pristup |
| Vektor | Složenost | Autentikacija |
| NETWORK |
HIGH |
NONE |
|
| Impact |
| Povjerljivost | Cjelovitost | Dostupnost |
| COMPLETE |
COMPLETE |
COMPLETE |
|
| CVSS vektor |
AV:N/AC:H/Au:N/C:C/I:C/A:C |
| Zadnje važnije ažuriranje |
18-08-2021 - 13:45 |
| Objavljeno |
17-08-2021 - 22:15 |