CVE-2014-8329

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
20/10/2014
Last modified:
12/04/2025

Description

Schrack Technik microControl with firmware before 1.7.0 (937) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain access data for the ftp and telnet services via a direct request for ZTPUsrDtls.txt.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:schrack:technik_microcontrol_firmware:*:*:*:*:*:*:*:* 1.7.0 (including)
cpe:2.3:h:schrack:technik_microcontrol:-:*:*:*:*:*:*:*