PT-2021-8574 · Ingeteam · Ingepac Da Au Auc

Published

2021-10-25

·

Updated

2021-10-28

·

CVE-2017-20007

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ingeteam INGEPAC DA AU AUC versions 1.13.0.28 and earlier
Description The web application of the affected software allows access to a certain path containing sensitive information, which could be used by an attacker to execute more sophisticated attacks. An unauthenticated remote attacker with access to the device's web service could exploit this issue to obtain different configuration files.
Recommendations For versions 1.13.0.28 and earlier, restrict access to the web service to minimize the risk of exploitation. As a temporary workaround, consider limiting access to sensitive configuration files until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-20007

Affected Products

Ingepac Da Au Auc