eWON devices with firmware before 10.1s0 do not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2015/Dec/118 | mailing list |
http://packetstormsecurity.com/files/135069/eWON-XSS-CSRF-Session-Management-RBAC-Issues.html | |
http://ewon.biz/support/news/support/ewon-security-enhancement-7529-01 | vendor advisory |
https://ics-cert.us-cert.gov/advisories/ICSA-15-351-03 | third party advisory us government resource |
http://www.securityfocus.com/bid/79625 | vdb entry |