{"api_version":"1","generated_at":"2026-05-27T21:48:01+00:00","cve":"CVE-2015-3972","urls":{"html":"https://cve.report/CVE-2015-3972","api":"https://cve.report/api/cve/CVE-2015-3972.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-3972","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-3972"},"summary":{"title":"CVE-2015-3972","description":"The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, which makes it easier for remote attackers to obtain access via a brute-force attack.","state":"PUBLISHED","assigner":"icscert","published_at":"2015-10-28 10:59:06","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-254","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-15-265-03","name":"https://ics-cert.us-cert.gov/advisories/ICSA-15-265-03","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory","US Government Resource"],"title":"Janitza UMG Power Quality Measuring Products Vulnerabilities | ICS-CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-3972","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-3972","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"3972","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"janitza","cpe5":"umg_508","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"3972","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"janitza","cpe5":"umg_509","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"3972","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"janitza","cpe5":"umg_511","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"3972","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"janitza","cpe5":"umg_604","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"3972","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"janitza","cpe5":"umg_605","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T06:04:02.932Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-15-265-03"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-10-22T00:00:00.000Z","descriptions":[{"lang":"en","value":"The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, which makes it easier for remote attackers to obtain access via a brute-force attack."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2015-10-28T02:57:01.000Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"tags":["x_refsource_MISC"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-15-265-03"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2015-3972","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, which makes it easier for remote attackers to obtain access via a brute-force attack."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-15-265-03","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-15-265-03"}]}}}},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2015-3972","datePublished":"2015-10-28T10:00:00.000Z","dateReserved":"2015-05-12T00:00:00.000Z","dateUpdated":"2024-08-06T06:04:02.932Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-10-28 10:59:06","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-254","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:janitza:umg_508:-:*:*:*:*:*:*:*","matchCriteriaId":"0AAC1AC1-5748-4993-9159-0612414E3CA2"},{"vulnerable":true,"criteria":"cpe:2.3:h:janitza:umg_509:-:*:*:*:*:*:*:*","matchCriteriaId":"F6574840-AA64-4E4D-86D1-968EEEE0281C"},{"vulnerable":true,"criteria":"cpe:2.3:h:janitza:umg_511:-:*:*:*:*:*:*:*","matchCriteriaId":"DFC7F511-A110-4306-9594-A2CDD1304323"},{"vulnerable":true,"criteria":"cpe:2.3:h:janitza:umg_604:-:*:*:*:*:*:*:*","matchCriteriaId":"07C0FF49-A0BF-4141-A5D8-A139AEA86FE0"},{"vulnerable":true,"criteria":"cpe:2.3:h:janitza:umg_605:-:*:*:*:*:*:*:*","matchCriteriaId":"8D21FD36-E671-4766-969B-5C8E351A4493"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"3972","Ordinal":"1","Title":"CVE-2015-3972","CVE":"CVE-2015-3972","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"3972","Ordinal":"1","NoteData":"The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, which makes it easier for remote attackers to obtain access via a brute-force attack.","Type":"Description","Title":"CVE-2015-3972"},{"CveYear":"2015","CveId":"3972","Ordinal":"2","NoteData":"2015-10-28","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"3972","Ordinal":"3","NoteData":"2015-10-27","Type":"Other","Title":"Modified"}]}}}