6.5

CVE-2021-41543

A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The handling of log files in the web application of affected devices contains an information disclosure vulnerability which could allow logged in users to access sensitive files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SiemensClimatix Pol909 Firmware SwEditionadvanced_web_module Version < 11.36
   SiemensClimatix Pol909 Version-
SiemensClimatix Pol909 Firmware SwEditionadvanced_web_and_bacnet_module Version < 11.44
   SiemensClimatix Pol909 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.412
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.