PT-2019-14604 · Tripplite · Pdumh15At

Jim Becher

·

Publicado

2019-09-12

·

Atualizado

2025-03-21

·

CVE-2019-16261

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tripp Lite PDUMH15AT version 12.04.0053
Description The issue allows unauthenticated POST requests to the "/Forms/" directory. This can be exploited to change the manager or admin password, or to shut off power to an outlet.
Recommendations For version 12.04.0053, update to a newer firmware version to resolve the issue. As a temporary workaround, consider restricting access to the "/Forms/" directory to prevent unauthenticated POST requests. Avoid using the device until the update is applied to minimize the risk of exploitation.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-16261

Produtos afetados

Pdumh15At