PT-2023-8669 · Unknown · Osprey Pump Controller
Published
2023-03-28
·
Updated
2023-04-05
·
CVE-2023-28375
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Osprey Pump Controller version 1.01
Description
The issue is related to the disclosure of information via query strings, allowing a remote attacker to reveal protected information. Using a
GET parameter, attackers can disclose arbitrary files on the affected device, potentially revealing sensitive and system information.Recommendations
For Osprey Pump Controller version 1.01, consider restricting access to the
GET parameter to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the vulnerable GET parameter in the affected API endpoint until the issue is resolved.Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Osprey Pump Controller