CVE-2019-15859

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
09/10/2019
Last modified:
24/08/2020

Description

Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the /password.jsn URI.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:socomec:diris_a-40_firmware:*:*:*:*:*:*:*:* 48250501 (excluding)
cpe:2.3:h:socomec:diris_a-40:-:*:*:*:*:*:*:*