Vulnerability Description
Schrack Technik microControl with firmware before 1.7.0 (937) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain access data for the ftp and telnet services via a direct request for ZTPUsrDtls.txt.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schrack | Technik Microcontrol Firmware | <= 1.7.0 |
| Schrack | Technik Microcontrol | - |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2014/Jul/40
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20140710-
- http://seclists.org/fulldisclosure/2014/Jul/40
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20140710-
FAQ
What is CVE-2014-8329?
CVE-2014-8329 is a vulnerability with a CVSS score of 10.0 (HIGH). Schrack Technik microControl with firmware before 1.7.0 (937) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain access data for ...
How severe is CVE-2014-8329?
CVE-2014-8329 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-8329?
Check the references section above for vendor advisories and patch information. Affected products include: Schrack Technik Microcontrol Firmware, Schrack Technik Microcontrol.