CVE-2019-18865

MEDIUM

Blaauw Remote Kiln Control <v3.00r4 - Info Disclosure

Title source: llm
STIX 2.1

Description

Information disclosure via error message discrepancies in authentication functions in Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to enumerate valid usernames.

References (2)

Core 2

Scores

CVSS v3 5.3
EPSS 0.0043
EPSS Percentile 62.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-209
Status published
Products (2)
blaauwproducts/remote_kiln_control 3.0.0 (2 CPE variants)
blaauwproducts/remote_kiln_control < 3.0.0
Published May 07, 2020
Tracked Since Feb 18, 2026