Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 provides different error messages for failed login attempts in unspecified circumstances, which allows remote attackers to obtain sensitive information via a series of requests.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-15-300-02 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2015-10-28T10:00:00
Updated: 2024-08-06T08:06:31.293Z
Reserved: 2015-10-22T00:00:00
Link: CVE-2015-7902
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2015-10-28T10:59:22.580
Modified: 2015-10-28T18:33:53.923
Link: CVE-2015-7902
Redhat
No data.