HIGH · 7.5

CVE-2019-16274

DTEN D5 before 1.3 and D7 before 1.3 devices transfer customer data files via unencrypted HTTP.

Vulnerability Description

DTEN D5 before 1.3 and D7 before 1.3 devices transfer customer data files via unencrypted HTTP.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
DtenD5 Firmware< 1.3
DtenD5-
DtenD7 Firmware< 1.3
DtenD7-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-16274?

CVE-2019-16274 is a vulnerability with a CVSS score of 7.5 (HIGH). DTEN D5 before 1.3 and D7 before 1.3 devices transfer customer data files via unencrypted HTTP.

How severe is CVE-2019-16274?

CVE-2019-16274 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-16274?

Check the references section above for vendor advisories and patch information. Affected products include: Dten D5 Firmware, Dten D5, Dten D7 Firmware, Dten D7.