An Information Exposure issue was discovered in Trihedral VTScada Versions prior to 11.2.26. Some files are exposed within the web server application to unauthenticated users. These files may contain sensitive configuration information.
oryginał ENCVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NTrihedral Vtscada
APPTrihedral≤ 11.2.23
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Powiązane podatności
CVE-2016-4510CRITICAL9.1PL ✓ten sam produkt
Auth Bypass w interfejsie WAP Trihedral VTScada — odczyt dowolnych plików
CVE-2016-4532CRITICAL9.1PL ✓ten sam produkt
Path Traversal w interfejsie WAP Trihedral VTScada – odczyt dowolnych plików
CVE-2016-4523HIGH7.5⚠ KEVten sam produkt
The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers ...
CVE-2022-3181HIGH7.5ten sam produkt
An Improper Input Validation vulnerability exists in Trihedral VTScada version 12.0.38 and prior. A specifical...
CVE-2017-14029HIGH7.8ten sam produkt
An Uncontrolled Search Path Element issue was discovered in Trihedral VTScada 11.3.03 and prior. The program w...