Impact
The XING CPTrans-ME-X device has a vulnerability that allows an attacker to expose sensitive system information to an unauthorized control sphere. This flaw can lead to the leakage of confidential system data, potentially allowing attackers to gain deeper insight into the device’s configuration or environment. The weakness is identified as CWE-497, which generally indicates a failure to protect sensitive data from unauthorized disclosure.
Affected Systems
The affected product is XING CPTrans-ME-X. No specific revision or firmware version information is given in the advisory, so all deployed variants of the CPTrans-ME-X may be at risk until official guidance is obtained.
Risk and Exploitability
The CVSS score of 8.7 denotes a high severity and indicates significant risk to confidentiality. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, so the current exploitation likelihood cannot be quantified precisely. The attack vector is not explicitly defined in the data; it is therefore inferred that the flaw could be exploited from the same network or system the device is connected to, or potentially from a remote management interface if exposed.
OpenCVE Enrichment