CVE-2020-15794

A vulnerability has been identified in Desigo Insight (All versions). Some error messages in the web application show the absolute path to the requested resource. This could allow an authenticated attacker to retrieve additional information about the host system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:desigo_insight:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:desigo_insight:6.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:desigo_insight:6.0:sp2:*:*:*:*:*:*
cpe:2.3:a:siemens:desigo_insight:6.0:sp3:*:*:*:*:*:*
cpe:2.3:a:siemens:desigo_insight:6.0:sp5:*:*:*:*:*:*

History

21 Nov 2024, 05:06

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/pdf/ssa-226339.pdf - Vendor Advisory () https://cert-portal.siemens.com/productcert/pdf/ssa-226339.pdf - Vendor Advisory
References () https://us-cert.cisa.gov/ics/advisories/icsa-20-287-05 - Third Party Advisory, US Government Resource () https://us-cert.cisa.gov/ics/advisories/icsa-20-287-05 - Third Party Advisory, US Government Resource

Information

Published : 2020-10-15 19:15

Updated : 2024-11-21 05:06


NVD link : CVE-2020-15794

Mitre link : CVE-2020-15794

CVE.ORG link : CVE-2020-15794


JSON object : View

Products Affected

siemens

  • desigo_insight
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-209

Generation of Error Message Containing Sensitive Information