A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exacqVision Web Service and the operating system.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-14402 A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exacqVision Web Service and the operating system.
Fixes

Solution

Upgrade all versions of exacqVision Web Service to v21.03.3 or later. Web Service 21.03.3 or later will only provide a full response to health.web info when authorized. Users can obtain the software update by downloading the update found here: https://exacq.com/support/downloads.php.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2024-09-17T03:23:48.351Z

Reserved: 2021-02-24T00:00:00

Link: CVE-2021-27656

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-03-18T18:15:13.827

Modified: 2024-11-21T05:58:23.177

Link: CVE-2021-27656

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.