Vulnerability Description
Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different functions of the web application via requests that lack certain mandatory parameters. This affects ifaces-diag.asp, system.asp, backup.asp, sys-power.asp, ifaces-wls.asp, ifaces-wls-pkt.asp, and ifaces-wls-pkt-adv.asp.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Westermo | Mrd-315 Firmware | 1.7.3 |
| Westermo | Mrd-315 | - |
References
- https://sku11army.blogspot.com/2020/01/westermo-source-code-disclousure-in.htmlExploitThird Party Advisory
- https://sku11army.blogspot.com/2020/01/westermo-source-code-disclousure-in.htmlExploitThird Party Advisory
FAQ
What is CVE-2020-7227?
CVE-2020-7227 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different functions of the web applica...
How severe is CVE-2020-7227?
CVE-2020-7227 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7227?
Check the references section above for vendor advisories and patch information. Affected products include: Westermo Mrd-315 Firmware, Westermo Mrd-315.