HIGH · 10.0

CVE-2014-8329

Schrack Technik microControl with firmware before 1.7.0 (937) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain access data for ...

Vulnerability Description

Schrack Technik microControl with firmware before 1.7.0 (937) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain access data for the ftp and telnet services via a direct request for ZTPUsrDtls.txt.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
SchrackTechnik Microcontrol Firmware<= 1.7.0
SchrackTechnik Microcontrol-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-8329?

CVE-2014-8329 is a vulnerability with a CVSS score of 10.0 (HIGH). Schrack Technik microControl with firmware before 1.7.0 (937) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain access data for ...

How severe is CVE-2014-8329?

CVE-2014-8329 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-8329?

Check the references section above for vendor advisories and patch information. Affected products include: Schrack Technik Microcontrol Firmware, Schrack Technik Microcontrol.