7.8

CVE-2013-4733

The web server on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 allows remote attackers to obtain sensitive configuration and status information by reading log files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Digital Alert Systems ≫ Dasdec Eas Version <= 2.0-1
Digital Alert Systems ≫ Dasdec Eas Version 2.0-0
Monroe Electronics ≫ R189 One-net Eas Version <= 2.0-1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.26% 0.811
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:C/I:N/A:N
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

http://www.digitalalertsystems.com/pdf/130604-Monroe-Security-PR.pdf
Vendor Advisory
http://www.kb.cert.org/vuls/id/662676
US Government Resource
http://www.kb.cert.org/vuls/id/AAMN-98MU7H
US Government Resource
http://www.kb.cert.org/vuls/id/AAMN-98MUK2
US Government Resource
http://www.monroe-electronics.com/MONROE_ELECTRONICS_PDF/130604-Monroe-Security-PR.pdf
Vendor Advisory