Record summary

CVE-2019-15859 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the /password.jsn URI.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryCRITICALSocomec DIRIS A-40 Devices Password DisclosureCVSS 9.8

Socomec DIRIS A-40 devices before 48250501 are susceptible to a password disclosure vulnerability in the web interface that could allow remote attackers to get full access to a device via the /password.jsn URI.

Impact

An attacker can obtain sensitive information such as passwords, leading to unauthorized access.

Remediation

Update the firmware of the Socomec DIRIS A-40 devices to the latest version to mitigate the vulnerability.

WeaknessesCWE-200
Authorsgeeknik
Template tagscvecve2019seclistspacketstormdisclosuresocomecdirisiotvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:socomec:diris_a-40_firmware:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

4