An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authentication before it can be interacted with, a large portion of the HTTP endpoints are missing authentication. An attacker is able to view these pages before being authenticated, and some of these pages may disclose sensitive information.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-03-17T20:51:20
Updated: 2024-08-05T11:58:18.174Z
Reserved: 2018-12-19T00:00:00
Link: CVE-2018-20220
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-03-21T16:00:35.407
Modified: 2024-11-21T04:01:06.570
Link: CVE-2018-20220
Redhat
No data.