The product exposes a service that is intended for local only to all network interfaces without any authentication.
El producto expone un servicio destinado únicamente al nivel local para todas las interfaces de red sin ninguna autenticación.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-306
|
| [email protected] | Primary |
en
CWE-306
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| hitachienergy | microscada_x_sys600 | * | <built-in method update of dict object at 0x72a9ccd2bdc0> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:hitachienergy:microscada_x_sys600:*:*:*:*:*:*:*:* |