An issue was discovered in OmniMetrix OmniView, Version 1.2. The OmniView web application transmits credentials with the HTTP protocol, which could be sniffed by an attacker that may result in the compromise of account credentials.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-16-350-02 | Mitigation Third Party Advisory US Government Resource |
http://www.securityfocus.com/bid/94937 | VDB Entry Third Party Advisory |
Configurations
Information
Published : 2017-02-13 13:59
Updated : 2017-02-17 05:52
NVD link : CVE-2016-5786
Mitre link : CVE-2016-5786
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
omnimetrix
- omniview