Impact
HTTP headers added by the default IIS and ASP.NET configuration for PcVue WebVue, WebScheduler, TouchVue and SnapVue services expose unnecessary sensitive information about the server configuration. This disclosure does not directly allow code execution or denial of service, but it provides an attacker with details that could aid in further exploitation. The weakness corresponds to CWE-201. The potential impact is primarily confidentiality of deployment details, with low likelihood of immediate compromise.
Affected Systems
The vulnerability affects PcVue installations from version 12.0.0 through 16.3.3, inclusive. ARC Informatique’s PcVue product contains the related ASP.NET components that emit the headers. Versions 16.3.4 and 15.2.14 provide a patched release that removes the exposed headers; any earlier releases remain affected.
Risk and Exploitability
The CVSS score is 2.3, indicating low severity. EPSS is less than 1 %, showing a very low likelihood of real‑world exploitation, and the vulnerability is not listed in CISA’s KEV catalog. It is inferred that the attack vector is remote, via HTTP requests to the affected web services. Without further exploitation, the risk remains low, but the exposed information could assist attackers in planning subsequent attacks.
OpenCVE Enrichment