Loading product vulnerabilities…
Total
4
Critical
2
High
2
Medium
0
CISA KEV
0
SENEC Storage Box V1,V2 and V3 accidentially expose a management UI accessible with publicly known admin credentials.
The affected devices use publicly available default credentials with administrative privileges.
The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture and modify network traffic.
In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensitive data.