CVE-2017-20007

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/10/2021
Last modified:
28/10/2021

Description

Ingeteam INGEPAC DA AU AUC_1.13.0.28 (and before) web application allows access to a certain path that contains sensitive information that could be used by an attacker to execute more sophisticated attacks. An unauthenticated remote attacker with access to the device´s web service could exploit this vulnerability in order to obtain different configuration files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ingeteam:ingepac_da_au_firmware:*:*:*:*:*:*:*:* auc_1.13.0.28 (including)
cpe:2.3:h:ingeteam:ingepac_da_au:-:*:*:*:*:*:*:*