Vulnerability Description
The webreport generation feature in the Danfoss AK-EM100 allows an unauthorized actor to generate a web report that discloses sensitive information such as the internal IP address, usernames and internal device values.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Danfoss | Ak-Em100 Firmware | < 2.2.0.12 |
| Danfoss | Ak-Em100 | - |
Related Weaknesses (CWE)
References
- https://csirt.divd.nl/CVE-2023-25912/
- https://csirt.divd.nl/DIVD-2023-00021/
- https://csirt.divd.nl/DIVD-2023-00021
- https://divd.nl/cves/CVE-2023-25912
FAQ
What is CVE-2023-25912?
CVE-2023-25912 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The webreport generation feature in the Danfoss AK-EM100 allows an unauthorized actor to generate a web report that discloses sensitive information such as the internal IP address, usernames and inter...
How severe is CVE-2023-25912?
CVE-2023-25912 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-25912?
Check the references section above for vendor advisories and patch information. Affected products include: Danfoss Ak-Em100 Firmware, Danfoss Ak-Em100.