CVE Published: 05/11/2024 |
CVE Updated: 05/11/2024 |
CVE Year: 2023 Source: ASRG |
Vendor: Enel X |
Product: JuiceBox Pro 3.0 22kW Cellular Status : PUBLISHED
CVE-2023-29126 Description
The Waybox Enel X web management application contains a PHP-type juggling vulnerability that may allow a brute force process and under certain conditions bypass authentication.
Metrics
CVSS Version: 3.1 |
Base Score: 4.2 MEDIUM Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N