6.5
CVE-2021-41543
- EPSS 0.22%
- Veröffentlicht 08.03.2022 12:15:10
- Zuletzt bearbeitet 21.11.2024 06:26:23
- Quelle productcert@siemens.com
- CVE-Watchlists
- Unerledigt
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The handling of log files in the web application of affected devices contains an information disclosure vulnerability which could allow logged in users to access sensitive files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siemens ≫ Climatix Pol909 Firmware SwEditionadvanced_web_module Version < 11.36
Siemens ≫ Climatix Pol909 Firmware SwEditionadvanced_web_and_bacnet_module Version < 11.44
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.412 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.