PT-2016-5096 · Accuenergy · Accuenergy Acuvim Ii Net

Maxim Rupp

·

Published

2016-04-21

·

Updated

2016-04-28

·

CVE-2016-2293

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Accuenergy Acuvim II NET Firmware versions 3.08 Accuenergy Acuvim IIR NET Firmware versions 3.08
Description The issue allows remote attackers to discover settings via a direct request to an unspecified URL. This could potentially expose sensitive information.
Recommendations For Accuenergy Acuvim II NET Firmware version 3.08, update to a newer version that addresses this issue. For Accuenergy Acuvim IIR NET Firmware version 3.08, update to a newer version that addresses this issue. As a temporary workaround, consider restricting access to the affected module to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-2293

Affected Products

Accuenergy Acuvim Ii Net