SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized attacker could read sensitive data from the system by querying for known files using the REST API directly.
References
Configurations
History
21 Nov 2024, 05:24
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.sick.com/de/en/service-and-support/the-sick-product-security-incident-response-team-sick-psirt/w/psirt/#advisories - Vendor Advisory |
Information
Published : 2020-07-29 14:15
Updated : 2024-11-21 05:24
NVD link : CVE-2020-2077
Mitre link : CVE-2020-2077
CVE.ORG link : CVE-2020-2077
JSON object : View
Products Affected
sick
- package_analytics
CWE
CWE-276
Incorrect Default Permissions