A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause unauthorized access when a low privileged user makes unauthorized changes.
Una CWE-863: Se presenta una vulnerabilidad de autorización incorrecta en U.motion Servers and Touch Panels (versiones afectadas listadas en la notificación de seguridad) que podrían causar un acceso no autorizado cuando un usuario poco privilegiado realiza cambios no autorizados
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | HIGH |
| Availability Impact | NONE |
AV:N/AC:L/Au:S/C:N/I:P/A:N
| Access Vector | NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | SINGLE |
| Confidentiality Impact | NONE |
| Integrity Impact | PARTIAL |
| Availability Impact | NONE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-863
|
| [email protected] | Primary |
en
CWE-863
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| schneider-electric | mtn6501-0001_firmware | * | <built-in method update of dict object at 0x7e610844db40> | Operating System |
| schneider-electric | mtn6501-0002_firmware | * | <built-in method update of dict object at 0x7e60a88965c0> | Operating System |
| schneider-electric | mtn6260-0410_firmware | * | <built-in method update of dict object at 0x7e6071ebb8c0> | Operating System |
| schneider-electric | mtn6260-0415_firmware | * | <built-in method update of dict object at 0x7e6110f85c40> | Operating System |
| schneider-electric | mtn6260-0310_firmware | * | <built-in method update of dict object at 0x7e6110f84540> | Operating System |
| schneider-electric | mtn6260-0315_firmware | * | <built-in method update of dict object at 0x7e610844ff40> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:mtn6501-0001_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:mtn6501-0001:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:mtn6501-0002_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:mtn6501-0002:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:mtn6260-0410_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:mtn6260-0410:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:mtn6260-0415_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:mtn6260-0415:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:mtn6260-0310_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:mtn6260-0310:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:mtn6260-0315_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:mtn6260-0315:-:*:*:*:*:*:*:* |