SB2018090707 - Information disclosure vulnerabilities in Ice Qube Thermal Management Center
Published: September 7, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Improper authentication (CVE-ID: CVE-2017-14026)
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to the web application does not properly authenticate users. A remote attacker can bypass authentication and gain access to potentially sensitive information.
2) Unprotected storage of credentials (CVE-ID: CVE-2017-16714)
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to the passwords are stored in plaintext in a file that is accessible without authentication. A remote attacker can gain access to potentially sensitive information.
Remediation
Install update from vendor's website.