Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-436f-chr9-2p6r

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.

The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.

EPSS

Процентиль: 50%
0.0027
Низкий

Дефекты

CWE-284
CWE-306

Связанные уязвимости

nvd
около 11 лет назад

The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.

EPSS

Процентиль: 50%
0.0027
Низкий

Дефекты

CWE-284
CWE-306