Improper access control in Industrial Network Director - CVE-2019-1976
Published: September 5, 2019 / Updated: September 5, 2019
Industrial Network Director
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists in the “plug-and-play” services component due to improper access restrictions on the web-based management interface. A remote attacker can send a specially crafted HTTP request to the target device and gain access to the running configuration information about devices managed by the IND, including administrative credentials.