CVE-2019-15859
Socomec DIRIS A-40 Devices Password Disclosure
Record summary
CVE-2019-15859 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the /password.jsn URI.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALSocomec DIRIS A-40 Devices Password DisclosureCVSS 9.8
Socomec DIRIS A-40 devices before 48250501 are susceptible to a password disclosure vulnerability in the web interface that could allow remote attackers to get full access to a device via the /password.jsn URI.
Impact
An attacker can obtain sensitive information such as passwords, leading to unauthorized access.
Remediation
Update the firmware of the Socomec DIRIS A-40 devices to the latest version to mitigate the vulnerability.
Source: ProjectDiscovery