All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) configuration that could abuse this vulnerability, allowing the attacker to retrieve limited confidential information through sniffing.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-20-254-03 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2020-09-18T18:04:16
Updated: 2024-08-04T13:37:54.179Z
Reserved: 2020-07-31T00:00:00
Link: CVE-2020-16230
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-09-18T19:15:16.153
Modified: 2024-11-21T05:06:59.127
Link: CVE-2020-16230
Redhat
No data.