Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-13941


A vulnerability has been identified in OZW672 (All versions < V10.00), OZW772 (All versions < V10.00). Vulnerable versions of OZW Web Server use predictable path names for project files that legitimately authenticated users have created by using the application's export function. By accessing a specific uniform resource locator on the web server, a remote attacker could be able to download a project file without prior authentication. The security vulnerability could be exploited by an unauthenticated attacker with network access to the affected system. No user interaction is required to exploit this security vulnerability. Successful exploitation of the security vulnerability compromises the confidentiality of the targeted system.


Published

2020-02-11T16:15:14.897

Last Modified

2024-11-21T04:25:44.447

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-552
  • Type: Primary
    CWE-552

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System siemens ozw672_firmware < 10.00 Yes
Hardware siemens ozw672 - No
Operating System siemens ozw772_firmware < 10.00 Yes
Hardware siemens ozw772 - No

References