Описание
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authentication before it can be interacted with, a large portion of the HTTP endpoints are missing authentication. An attacker is able to view these pages before being authenticated, and some of these pages may disclose sensitive information.
Ссылки
- Third Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
- Not Applicable
- Third Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
- Not Applicable
Уязвимые конфигурации
Одновременно
Одновременно
Одновременно
EPSS
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
Связанные уязвимости
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authentication before it can be interacted with, a large portion of the HTTP endpoints are missing authentication. An attacker is able to view these pages before being authenticated, and some of these pages may disclose sensitive information.
EPSS
7.5 High
CVSS3
5 Medium
CVSS2