Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated file disclosure. Using a GET parameter, attackers can disclose arbitrary files on the affected device and disclose sensitive and system information.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 16 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-16T21:38:35.314Z
Reserved: 2023-03-21T21:17:06.873Z
Link: CVE-2023-28375
Updated: 2024-08-02T12:38:25.071Z
Status : Modified
Published: 2023-03-28T21:15:10.950
Modified: 2024-11-21T07:54:57.003
Link: CVE-2023-28375
No data.
OpenCVE Enrichment
No data.
Weaknesses