CVE-2022-47070

HIGH

nvs-365-v01_firmware - Unauthenticated Exposure of Sensitive Information via Password Validation Response

Title source: llm
STIX 2.1

Description

NVS365 V01 is vulnerable to Incorrect Access Control. After entering a wrong password, the url will be sent to the server twice. In the second package, the server will return the correct password information.

Scores

CVSS v3 7.5
EPSS 0.0085
EPSS Percentile 53.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
nvs365/nvs-365-v01_firmware
Published Feb 03, 2023
Tracked Since Feb 18, 2026