← Retour aux CVEs
CVE-2021-41543
MEDIUM6.5
Description
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The handling of log files in the web application of affected devices contains an information disclosure vulnerability which could allow logged in users to access sensitive files.
Details CVE
Score CVSS v3.16.5
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie3/8/2022
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
siemens:climatix_pol909siemens:climatix_pol909_firmware
Faiblesses (CWE)
CWE-284CWE-532
References
https://cert-portal.siemens.com/productcert/pdf/ssa-252466.pdf(productcert@siemens.com)
https://cert-portal.siemens.com/productcert/pdf/ssa-252466.pdf(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.