Environmental Systems Corporation (ESC) 8832 Data Controller 3.02 and earlier mishandles sessions, which allows remote attackers to bypass authentication and make arbitrary configuration changes via unspecified vectors.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-16-147-01 | Third Party Advisory US Government Resource |
Configurations
Information
Published : 2016-05-30 18:59
Updated : 2016-06-07 07:23
NVD link : CVE-2016-4501
Mitre link : CVE-2016-4501
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
envirosys
- esc_8832_data_controller