This content is restricted.
Brief
Here is a summary of the provided document using the provided template:
Summary:
The View CSAF document details two vulnerabilities in the Gessler GmbH WEB-MASTER emergency lighting management system. The first vulnerability, CVE-2024-1039, is a use of weak credentials in the restoration account, allowing an attacker to gain control over the device's web management. The second vulnerability, CVE-2024-1040, is a use of weak hashing algorithms for user account passwords, allowing an attacker to break the hashes and extract passwords. Both vulnerabilities have high CVSS scores, with the first scoring a 9.8 and the second scoring a 4.4. The recommended mitigation is to update the device to version 4.4 or greater, and CISA provides additional guidance on cybersecurity best practices for critical infrastructure sectors.
Highlights content goes here...
This content is restricted.
