PT-2013-4447 · Groundwork+1 · Groundwork Monitor Enterprise+1

Publicado

2013-05-08

·

Atualizado

2013-05-08

·

CVE-2013-3512

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GroundWork Monitor Enterprise version 6.7.0
Description The issue concerns improper authorization checks in the Cacti component, allowing remote authenticated users to read or modify configuration settings. This can be exploited to read credentials.
Recommendations For GroundWork Monitor Enterprise version 6.7.0, update to a version that properly performs authorization checks to prevent unauthorized access to configuration settings.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-3512

Produtos afetados

Cacti
Groundwork Monitor Enterprise