6.5

CVE-2020-12496

ENDRESS+HAUSER: Ecograph T utilizing Webserver firmware version 2.x exposures sensitive information to an unauthorized actor

Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) and Memograph M (Neutral/Private Label) (RSG45, ORSG45) with Firmware version V2.0.0 and above is prone to exposure of sensitive information to an unauthorized actor. The firmware release has a dynamic token for each request submitted to the server, which makes repeating requests and analysis complex enough. Nevertheless, it's possible and during the analysis it was discovered that it also has an issue with the access-control matrix on the server-side. It was found that a user with low rights can get information from endpoints that should not be available to this user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Endress ≫ Rsg35 Firmware Version < 2.0.0
   Endress ≫ Rsg35 Version -
Endress ≫ Rsg45 Firmware Version < 2.0.0
   Endress ≫ Rsg45 Version -
Endress ≫ Orsg35 Firmware Version < 2.0.0
   Endress ≫ Orsg35 Version -
Endress ≫ Orsg45 Firmware Version < 2.0.0
   Endress ≫ Orsg45 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.84% 0.546
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
info@cert.vde.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://cert.vde.com/en-us/advisories/vde-2020-022
Vendor Advisory