CVE-2019-16261
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
12/09/2019
Last modified:
21/03/2025
Description
Tripp Lite PDUMH15AT 12.04.0053 and SU750XL 12.04.0052 devices allow unauthenticated POST requests to the /Forms/ directory, as demonstrated by changing the manager or admin password, or shutting off power to an outlet. NOTE: the vendor's position is that a newer firmware version, fixing this vulnerability, had already been released before this vulnerability report about 12.04.0053.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Base Score 2.0
8.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:tripplite:pdumh15at_firmware:12.04.0053:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tripplite:pdumh15at:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



