PT-2015-7664 · Honeywell · Honeywell Midas Black Gas Detectors+1
Publicado
2015-12-21
·
Atualizado
2015-12-22
·
CVE-2015-7907
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Honeywell Midas gas detectors versions prior to 1.13b3
Honeywell Midas Black gas detectors versions prior to 2.13b3
Description
A directory traversal issue in the web server of Honeywell gas detectors allows remote attackers to bypass authentication. This can lead to writing to a configuration file or triggering a calibration or test via unspecified vectors.
Recommendations
For Honeywell Midas gas detectors versions prior to 1.13b3, update to version 1.13b3 or later to resolve the issue.
For Honeywell Midas Black gas detectors versions prior to 2.13b3, update to version 2.13b3 or later to resolve the issue.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Honeywell Midas Black Gas Detectors
Honeywell Midas Gas Detectors