Vulnerability Description
Directory traversal vulnerability in the web server on Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allows remote attackers to bypass authentication, and write to a configuration file or trigger a calibration or test, via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Honeywell | Midas Black Firmware | <= 2.13b1 |
| Honeywell | Midas Firmware | <= 1.13b1 |
Related Weaknesses (CWE)
References
- https://ics-cert.us-cert.gov/advisories/ICSA-15-309-02Third Party AdvisoryUS Government Resource
- https://ics-cert.us-cert.gov/advisories/ICSA-15-309-02Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2015-7907?
CVE-2015-7907 is a vulnerability with a CVSS score of 8.6 (HIGH). Directory traversal vulnerability in the web server on Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allows remote attackers to bypass authentication, and wri...
How severe is CVE-2015-7907?
CVE-2015-7907 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-7907?
Check the references section above for vendor advisories and patch information. Affected products include: Honeywell Midas Black Firmware, Honeywell Midas Firmware.