Vulnerability Description
dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Thermofisher | Dt80 Dex Firmware | 1.50.012 |
| Thermofisher | Dt80 Dex | - |
Related Weaknesses (CWE)
References
- https://packetstormsecurity.com/files/143328/DataTaker-DT80-dEX-1.50.012-SensitiExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/42313/Third Party AdvisoryVDB Entry
- https://packetstormsecurity.com/files/143328/DataTaker-DT80-dEX-1.50.012-SensitiExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/42313/Third Party AdvisoryVDB Entry
FAQ
What is CVE-2017-11165?
CVE-2017-11165 is a vulnerability with a CVSS score of 9.8 (CRITICAL). dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI.
How severe is CVE-2017-11165?
CVE-2017-11165 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-11165?
Check the references section above for vendor advisories and patch information. Affected products include: Thermofisher Dt80 Dex Firmware, Thermofisher Dt80 Dex.