5
CVE-2014-2356
- EPSS 1.76%
- Veröffentlicht 30.07.2014 14:55:06
- Zuletzt bearbeitet 03.10.2025 18:15:32
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
Innominate mGuard before 7.6.4 and 8.x before 8.0.3 does not require authentication for snapshot downloads, which allows remote attackers to obtain sensitive information via a crafted HTTPS request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Innominate ≫ Mguard Firmware Version <= 7.5.0
Innominate ≫ Mguard Firmware Version4.0.4
Innominate ≫ Mguard Firmware Version4.1.1
Innominate ≫ Mguard Firmware Version4.2.3
Innominate ≫ Mguard Firmware Version5.0.1
Innominate ≫ Mguard Firmware Version5.1.6
Innominate ≫ Mguard Firmware Version6.0.2
Innominate ≫ Mguard Firmware Version6.1.5
Innominate ≫ Mguard Firmware Version7.0.2
Innominate ≫ Mguard Firmware Version7.1.1
Innominate ≫ Mguard Firmware Version7.2.1
Innominate ≫ Mguard Firmware Version7.3.1
Innominate ≫ Mguard Firmware Version7.4.1
Innominate ≫ Mguard Firmware Version8.0.0
Innominate ≫ Mguard Firmware Version8.0.1
Innominate ≫ Mguard Firmware Version8.0.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.76% | 0.819 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
| ics-cert@hq.dhs.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.