PT-2022-11425 · Unknown · Climatix Pol909

Published

2022-03-08

·

Updated

2022-03-11

·

CVE-2021-41543

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Climatix POL909 (AWB module) versions prior to V11.44 Climatix POL909 (AWM module) versions prior to V11.36
Description A vulnerability has been identified in the handling of log files in the web application of affected devices, which contains an information disclosure issue. This could allow logged in users to access sensitive files.
Recommendations For Climatix POL909 (AWB module) versions prior to V11.44, update to version V11.44 or later to resolve the issue. For Climatix POL909 (AWM module) versions prior to V11.36, update to version V11.36 or later to resolve the issue.

Fix

Insertion into Log File

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41543

Affected Products

Climatix Pol909