PT-2021-8574 · Ingeteam · Ingepac Da Au Auc
Published
2021-10-25
·
Updated
2021-10-28
·
CVE-2017-20007
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ingeteam INGEPAC DA AU AUC versions 1.13.0.28 and earlier
Description
The web application of the affected software allows access to a certain path containing sensitive information, which could be used by an attacker to execute more sophisticated attacks. An unauthenticated remote attacker with access to the device's web service could exploit this issue to obtain different configuration files.
Recommendations
For versions 1.13.0.28 and earlier, restrict access to the web service to minimize the risk of exploitation. As a temporary workaround, consider limiting access to sensitive configuration files until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ingepac Da Au Auc