CVE-2022-34534
Digital Watchdog DW Spectrum Server 4.2.0.32842 - Information Disclosure
Record summary
CVE-2022-34534 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHDigital Watchdog DW Spectrum Server 4.2.0.32842 - Information DisclosureCVSS 7.5
Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.
Impact
Unauthenticated attackers can access sensitive system information including network configuration, remote addresses, and cloud host details through the moduleInformation API endpoint, potentially facilitating further attacks.
Remediation
Update Digital Watchdog DW Spectrum Server to a version newer than 4.2.0.32842 that requires authentication for the moduleInformation API endpoint.
Source: ProjectDiscovery