← Back

CVE-2019-6836

nvd nist
Published: Sep 17, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow the file system to access the wrong file.

Affected (4)

Meg6501 0001 Firmware
Meg6501 0002 Firmware
Meg6260 0410 Firmware
Meg6260 0415 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.3.7
Running on/withPlatform Versions
Schneider Electric
Meg6501 0001
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.3.7
Running on/withPlatform Versions
Schneider Electric
Meg6501 0002
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.3.7
Running on/withPlatform Versions
Schneider Electric
Meg6260 0410
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.3.7
Running on/withPlatform Versions
Schneider Electric
Meg6260 0415
All versions

References (2)

Timeline

No history available yet.