CVE-2015-7907
8.6
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Exploitability: 3.9 / Impact: 4.7
Source: NVD
Description
Directory traversal vulnerability in the web server on Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allows remote attackers to bypass authentication, and write to a configuration file or trigger a calibration or test, via unspecified vectors.
Affected (2)
Products: Honeywell: Midas Black Firmware, Midas Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.13b1 | |
| Up to 1.13b1 |
References (2)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.