SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized attacker could read sensitive data from the system by querying for known files using the REST API directly.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: SICK AG
Published: 2020-07-29T13:18:59
Updated: 2024-08-04T06:54:00.702Z
Reserved: 2019-12-04T00:00:00
Link: CVE-2020-2077
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-07-29T14:15:12.910
Modified: 2024-11-21T05:24:34.173
Link: CVE-2020-2077
Redhat
No data.