The InfoScan client download page can be intercepted with a proxy, to
expose filenames located on the system, which could lead to additional
information exposure.
Metrics
Affected Vendors & Products
References
History
Fri, 09 Aug 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dorsettcontrols
Dorsettcontrols infoscan |
|
CPEs | cpe:2.3:a:dorsettcontrols:infoscan:1.32:*:*:*:*:*:*:* cpe:2.3:a:dorsettcontrols:infoscan:1.33:*:*:*:*:*:*:* cpe:2.3:a:dorsettcontrols:infoscan:1.35:*:*:*:*:*:*:* |
|
Vendors & Products |
Dorsettcontrols
Dorsettcontrols infoscan |
|
Metrics |
ssvc
|
Thu, 08 Aug 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The InfoScan client download page can be intercepted with a proxy, to expose filenames located on the system, which could lead to additional information exposure. | |
Title | Dorsett Controls InfoScan Path Traversal | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2024-08-08T17:27:17.383Z
Updated: 2024-08-09T15:02:38.084Z
Reserved: 2024-08-05T16:34:29.403Z
Link: CVE-2024-42408
Vulnrichment
Updated: 2024-08-09T15:02:21.268Z
NVD
Status : Analyzed
Published: 2024-08-08T18:15:10.953
Modified: 2024-08-29T14:22:45.603
Link: CVE-2024-42408
Redhat
No data.