Логотип exploitDog
bind:CVE-2023-39466
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-39466

Количество 3

Количество 3

nvd логотип

CVE-2023-39466

почти 2 года назад

Triangle MicroWorks SCADA Data Gateway get_config Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. The specific flaw exists within the get_config endpoint. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose sensitive information. Was ZDI-CAN-20797.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-8vq2-42cx-f687

почти 2 года назад

Triangle MicroWorks SCADA Data Gateway get_config Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. The specific flaw exists within the get_config endpoint. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose sensitive information. Was ZDI-CAN-20797.

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2023-05465

больше 2 лет назад

Уязвимость компонента get_config программного средства обмена данными между системами SCADA Triangle MicroWorks SCADA Data Gateway (SDG), позволяющая нарушителю обойти ограничения безопасности и получить несанкционированный доступ к системе

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-39466

Triangle MicroWorks SCADA Data Gateway get_config Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. The specific flaw exists within the get_config endpoint. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose sensitive information. Was ZDI-CAN-20797.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-8vq2-42cx-f687

Triangle MicroWorks SCADA Data Gateway get_config Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. The specific flaw exists within the get_config endpoint. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose sensitive information. Was ZDI-CAN-20797.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
fstec логотип
BDU:2023-05465

Уязвимость компонента get_config программного средства обмена данными между системами SCADA Triangle MicroWorks SCADA Data Gateway (SDG), позволяющая нарушителю обойти ограничения безопасности и получить несанкционированный доступ к системе

CVSS3: 5.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу