CVE-2020-15794

MEDIUM

Desigo Insight - Authenticated Sensitive Information Exposure via Error Message

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in Desigo Insight (All versions). Some error messages in the web application show the absolute path to the requested resource. This could allow an authenticated attacker to retrieve additional information about the host system.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-20-287-05

Scores

CVSS v3 4.3
EPSS 0.0017
EPSS Percentile 38.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-209 CWE-200
Status published
Products (2)
siemens/desigo_insight 6.0 (4 CPE variants)
siemens/desigo_insight < 6.0
Published Oct 15, 2020
Tracked Since Feb 18, 2026