Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different functions of the web application via requests that lack certain mandatory parameters. This affects ifaces-diag.asp, system.asp, backup.asp, sys-power.asp, ifaces-wls.asp, ifaces-wls-pkt.asp, and ifaces-wls-pkt-adv.asp.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-01-18T18:42:03
Updated: 2024-08-04T09:25:48.516Z
Reserved: 2020-01-18T00:00:00
Link: CVE-2020-7227
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-01-18T19:15:11.167
Modified: 2024-11-21T05:36:52.353
Link: CVE-2020-7227
Redhat
No data.