Vulnerability Description
In EZCast Pro II, the administrator password md5 hash is provided upon a web request. This hash can be cracked to access the administration panel of the device.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Actions-Micro | Ezcast Pro Ii Firmware | - |
| Actions-Micro | Ezcast Pro Ii | - |
References
- https://digital.security/advisories/cert-ds_advisory-ezcast_pro_ii_admin_passworThird Party Advisory
- https://digital.security/advisories/cert-ds_advisory-ezcast_pro_ii_admin_passworThird Party Advisory
FAQ
What is CVE-2019-12305?
CVE-2019-12305 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In EZCast Pro II, the administrator password md5 hash is provided upon a web request. This hash can be cracked to access the administration panel of the device.
How severe is CVE-2019-12305?
CVE-2019-12305 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12305?
Check the references section above for vendor advisories and patch information. Affected products include: Actions-Micro Ezcast Pro Ii Firmware, Actions-Micro Ezcast Pro Ii.