Improper access control in Industrial Network Director - CVE-2019-1976

 

Improper access control in Industrial Network Director - CVE-2019-1976

Published: September 5, 2019 / Updated: September 5, 2019


Vulnerability identifier: #VU20868
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1976
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists in the “plug-and-play” services component due to improper access restrictions on the web-based management interface. A remote attacker can send a specially crafted HTTP request to the target device and gain access to the running configuration information about devices managed by the IND, including administrative credentials.





Affected software

Industrial Network Director

How to mitigate CVE-2019-1976

Install updates from vendor's website.

Industrial Network Director - update to 1.6.0

External References

Related Security Bulletins