CVE-2018-14822

CRITICAL

Entes EMG12 <2.57 - Info Disclosure

Title source: llm
STIX 2.1

Description

Entes EMG12 versions 2.57 and prior an information exposure through query strings vulnerability in the web interface has been identified, which may allow an attacker to impersonate a legitimate user and execute arbitrary code.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-18-275-03
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105489

Scores

CVSS v3 9.8
EPSS 0.0292
EPSS Percentile 85.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-200 CWE-598
Status published
Products (1)
entes/emg-12_firmware < 2.57
Published Oct 02, 2018
Tracked Since Feb 18, 2026