Exposure of Sensitive Information vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to retrieve information about IP infrastructure and credentials. This issue affects EZD RP all versions before 19.6
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 17 Mar 2025 09:45:00 +0000


Mon, 17 Mar 2025 08:45:00 +0000


Fri, 23 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Nask
Nask ezd Rp
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:nask:ezd_rp:*:*:*:*:*:*:*:*
Vendors & Products Nask
Nask ezd Rp
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Wed, 07 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Aug 2024 11:15:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive Information vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to retrieve information about IP infrastructure and credentials. This issue affects EZD RP all versions before 19.6
Title Internal infrastructure data leak in EZD RP
Weaknesses CWE-213
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/R:A/V:D/RE:L/U:Green'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2025-03-17T08:35:32.535Z

Reserved: 2024-07-30T08:43:03.593Z

Link: CVE-2024-7267

cve-icon Vulnrichment

Updated: 2024-08-07T14:08:27.014Z

cve-icon NVD

Status : Modified

Published: 2024-08-07T11:15:46.200

Modified: 2025-03-17T09:15:12.470

Link: CVE-2024-7267

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.