Vulnerability Details CVE-2021-38462
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy. This may allow an attacker with obtained user credentials to enumerate passwords and impersonate other application users and perform operations on their behalf.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 44.9%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2021-38462
-
cpe:2.3:h:inhandnetworks:ir615:-
-
cpe:2.3:o:inhandnetworks:ir615_firmware:2.3.0.r4724
-
cpe:2.3:o:inhandnetworks:ir615_firmware:2.3.0.r4870