Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2015-7907

HIGH · 8.6 CVSS Gepubliceerd: CWE-22

Beschrijving NL

Directory traversal kwetsbaarheid in de webserver op Honeywell Midas gasdetectoren vóór 1.13b3 en Midas Black gasdetectoren vóór 2.13b3 stelt externe aanvallers in staat om authenticatie te omzeilen en naar een configuratiebestand te schrijven of een kalibratie of test te activeren, via niet-gespecificeerde vectoren.

Origineel (Engels) tonen

Directory traversal vulnerability in the web server on Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allows remote attackers to bypass authentication, and write to a configuration file or trigger a calibration or test, via unspecified vectors.

Vendors

Honeywell

Affected products

Midas Black Firmware Midas Firmware

References