SB2019061920 - Information disclosure in Optergy Enterprise Building Management System
Published: June 19, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2019-7272)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to username disclosure via its username reset functionality. A remote attacker can enumerate and disclose all the valid users on the system.
Furthermore, when calling a certain page from a remote location, the following internal information can be divulged for the current system: Name, Internal IP Address, Netmask, Hostname, Gateway, DNS Server, and DNS Server 2.
Remediation
Install update from vendor's website.