An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access internal information about status and connected devices without authenticating.
2017-08-07T08:29:00.243
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | abb | vsn300_firmware | ≤ 1.8.15 | Yes |
| Hardware | abb | vsn300 | - | No |
| Operating System | abb | vsn300_for_react_firmware | 2.1.3 | Yes |
| Hardware | abb | vsn300_for_react | - | No |