Brief

Here is a summary of the provided document using the provided template:

Summary:

The View CSAF document details two vulnerabilities in the Gessler GmbH WEB-MASTER emergency lighting management system. The first vulnerability, CVE-2024-1039, is a use of weak credentials in the restoration account, allowing an attacker to gain control over the device's web management. The second vulnerability, CVE-2024-1040, is a use of weak hashing algorithms for user account passwords, allowing an attacker to break the hashes and extract passwords. Both vulnerabilities have high CVSS scores, with the first scoring a 9.8 and the second scoring a 4.4. The recommended mitigation is to update the device to version 4.4 or greater, and CISA provides additional guidance on cybersecurity best practices for critical infrastructure sectors.

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 9.8 ATTENTION: Exploitable Remotely/Low attack complexity Vendor: Gessler GmbH Equipment: WEB-MASTER Vulnerabilities: Use of Weak Credentials, Use of Weak Hash 2. RISK EVALUATION Successful exploitation of these vulnerabilities could allow a user to take control of the web management of the device. An attacker with access to the

This content is restricted.

Highlights content goes here...

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 9.8 ATTENTION: Exploitable Remotely/Low attack complexity Vendor: Gessler GmbH Equipment: WEB-MASTER Vulnerabilities: Use of Weak Credentials, Use of Weak Hash 2. RISK EVALUATION Successful exploitation of these vulnerabilities could allow a user to take control of the web management of the device. An attacker with access to the

This content is restricted.

Cybersecurity and Infrastructure Security Agency

Quick Insight
RADA.AI
RADA.AI
Hello! I'm RADA.AI - Regulatory Analysis and Decision Assistance. Your Intelligent guide for compliance and decision-making. How can i assist you today?
Suggested

Form successfully submitted. One of our GRI rep will contact you shortly

Thanking You!

Enter your Email

Enter your registered username/email id.

Enter your Email

Enter your email id below to signup.
Individual Plan
$125 / month OR $1250 / year
Features
Best for: Researchers, Legal professionals, Academics
Enterprise Plan
Contact for Pricing
Features
Best for: Law Firms, Corporations, Government Bodies