PT-2023-8669 · Unknown · Osprey Pump Controller
CVE-2023-28375
·
Publicado
2023-03-28
·
Atualizado
2023-04-05
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Osprey Pump Controller version 1.01
Description
The issue is related to the disclosure of information via query strings, allowing a remote attacker to reveal protected information. Using a
GET parameter, attackers can disclose arbitrary files on the affected device, potentially revealing sensitive and system information.Recommendations
For Osprey Pump Controller version 1.01, consider restricting access to the
GET parameter to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the vulnerable GET parameter in the affected API endpoint until the issue is resolved.Correção
Files Accessible to External Parties
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Osprey Pump Controller