Exemys Telemetry Web Server relies on an HTTP Location header to indicate that a client is unauthorized, which allows remote attackers to bypass intended access restrictions by disregarding this header and processing the response body.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-15-321-01 | Third Party Advisory US Government Resource |
Configurations
Information
Published : 2015-11-19 03:59
Updated : 2015-11-19 11:08
NVD link : CVE-2015-7910
Mitre link : CVE-2015-7910
JSON object : View
CWE
Products Affected
exemys
- telemetry_web_server