HIGH · 7.8

CVE-2015-7910

Exemys Telemetry Web Server relies on an HTTP Location header to indicate that a client is unauthorized, which allows remote attackers to bypass intended access restrictions by disregarding this heade...

Vulnerability Description

Exemys Telemetry Web Server relies on an HTTP Location header to indicate that a client is unauthorized, which allows remote attackers to bypass intended access restrictions by disregarding this header and processing the response body.

CVSS Score

7.8

HIGH

AV:N/AC:L/Au:N/C:C/I:N/A:N
Confidentiality
COMPLETE
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
ExemysTelemetry Web ServerAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-7910?

CVE-2015-7910 is a vulnerability with a CVSS score of 7.8 (HIGH). Exemys Telemetry Web Server relies on an HTTP Location header to indicate that a client is unauthorized, which allows remote attackers to bypass intended access restrictions by disregarding this heade...

How severe is CVE-2015-7910?

CVE-2015-7910 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-7910?

Check the references section above for vendor advisories and patch information. Affected products include: Exemys Telemetry Web Server.