CVE-2025-46414
The affected product does not limit the number of attempts for inputting
the correct PIN for a registered product, which may allow an attacker
to gain unauthorized access using brute-force methods if they possess a
valid device serial number. The API provides clear feedback when the
correct PIN is entered. This vulnerability was patched in a server-side
update on April 6, 2025.
the correct PIN for a registered product, which may allow an attacker
to gain unauthorized access using brute-force methods if they possess a
valid device serial number. The API provides clear feedback when the
correct PIN is entered. This vulnerability was patched in a server-side
update on April 6, 2025.
Vendor
-
Product
-
CWE
Yayın Tarihi
2025-08-08 17:15:28
Güncelleme
2025-08-08 20:30:18
Source Identifier
ics-cert@hq.dhs.gov
KEV Date Added
-