PT-2015-7673 · Hms Industrial Networks · Ewon

Karn Ganeshen

·

Publicado

2015-12-23

·

Atualizado

2016-12-07

·

CVE-2015-7926

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions eWON devices versions prior to 10.1s0
Description The issue allows remote attackers to obtain sensitive information. This is due to the omission of Role-Based Access Control (RBAC) for I/O server information and status requests in affected devices. The attack can be performed via an unspecified URL.
Recommendations For versions prior to 10.1s0, update the firmware to version 10.1s0 or later to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-7926

Produtos afetados

Ewon