An issue was discovered in OmniMetrix OmniView, Version 1.2. The OmniView web application transmits credentials with the HTTP protocol, which could be sniffed by an attacker that may result in the compromise of account credentials.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/94937 | Third Party Advisory VDB Entry |
https://ics-cert.us-cert.gov/advisories/ICSA-16-350-02 | Mitigation Third Party Advisory US Government Resource |
http://www.securityfocus.com/bid/94937 | Third Party Advisory VDB Entry |
https://ics-cert.us-cert.gov/advisories/ICSA-16-350-02 | Mitigation Third Party Advisory US Government Resource |
Configurations
History
21 Nov 2024, 02:55
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/94937 - Third Party Advisory, VDB Entry | |
References | () https://ics-cert.us-cert.gov/advisories/ICSA-16-350-02 - Mitigation, Third Party Advisory, US Government Resource |
Information
Published : 2017-02-13 21:59
Updated : 2024-11-21 02:55
NVD link : CVE-2016-5786
Mitre link : CVE-2016-5786
CVE.ORG link : CVE-2016-5786
JSON object : View
Products Affected
omnimetrix
- omniview
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor