cause account takeover and unauthorized access to the system
when an attacker conducts brute-force attacks against the
equipment login. Note that the system supports only one concurrent session and implements a delay of more than a second
between failed login attempts making it difficult to automate the
attacks.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49869 | A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the equipment login. Note that the system supports only one concurrent session and implements a delay of more than a second between failed login attempts making it difficult to automate the attacks. |
Tue, 26 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hitachienergy
Hitachienergy nsd570 Firmware |
|
| CPEs | cpe:2.3:o:hitachienergy:nsd570_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hitachienergy
Hitachienergy nsd570 Firmware |
|
| Metrics |
ssvc
|
Tue, 26 Nov 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the equipment login. Note that the system supports only one concurrent session and implements a delay of more than a second between failed login attempts making it difficult to automate the attacks. | |
| Weaknesses | CWE-307 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Hitachi Energy
Published:
Updated: 2024-11-26T16:11:19.880Z
Reserved: 2024-10-14T11:03:53.306Z
Link: CVE-2024-9928
Updated: 2024-11-26T16:07:06.298Z
Status : Deferred
Published: 2024-11-26T14:15:22.777
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-9928
No data.
OpenCVE Enrichment
No data.
EUVD