The web server on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 allows remote attackers to obtain sensitive configuration and status information by reading log files.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/AAMN-98MUK2 | us government resource |
http://www.kb.cert.org/vuls/id/662676 | third party advisory us government resource |
http://www.kb.cert.org/vuls/id/AAMN-98MU7H | us government resource |
http://www.monroe-electronics.com/MONROE_ELECTRONICS_PDF/130604-Monroe-Security-PR.pdf | vendor advisory |
http://www.digitalalertsystems.com/pdf/130604-Monroe-Security-PR.pdf | vendor advisory |