PT-2015-6092 · Unknown · Thermostat

Published

2015-06-08

·

Updated

2023-02-13

·

CVE-2015-3201

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Thermostat versions prior to 2.0.0
Description The issue allows local users to obtain user credentials by reading the web.xml configuration file due to world-readable permissions.
Recommendations For versions prior to 2.0.0, update to version 2.0.0 or later to resolve the issue.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2015-3201
RHSA-2015:1052

Affected Products

Thermostat