6.5

CVE-2021-41543

A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The handling of log files in the web application of affected devices contains an information disclosure vulnerability which could allow logged in users to access sensitive files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siemens ≫ Climatix Pol909 Firmware SwEdition advanced_web_module Version < 11.36
   Siemens ≫ Climatix Pol909 Version -
Siemens ≫ Climatix Pol909 Firmware SwEdition advanced_web_and_bacnet_module Version < 11.44
   Siemens ≫ Climatix Pol909 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.75% 0.511
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

https://cert-portal.siemens.com/productcert/pdf/ssa-252466.pdf
Patch
Vendor Advisory