Authentication Bypass by Primary Weakness in Kiloview P1/P2 devices
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8epss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
The vulnerability allows attackers access to the root account without having to authenticate. Specifically, if the device is configured with the IP address of 10.10.10.10, the root user is automatically logged in.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Kiloview · P1/P2