CVE-2019-17219

HIGH

V-Zug Combi-Steam MSLQ Firmware < ethernet_r07 - Unauthenticated Network Access

Title source: llm
STIX 2.1

Description

An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the device does not enforce any authentication. An adjacent attacker is able to use the network interface without proper access control.

References (1)

Core 1
Core References
Permissions Required, Third Party Advisory x_refsource_misc
https://vuldb.com/?id.134115

Scores

CVSS v3 8.8
EPSS 0.0056
EPSS Percentile 42.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-306
Status published
Products (1)
vzug/combi-stream_mslq_firmware < ethernet_r07
Published Oct 06, 2019
Tracked Since Feb 18, 2026