An issue was discovered in OmniMetrix OmniView, Version 1.2. The OmniView web application transmits credentials with the HTTP protocol, which could be sniffed by an attacker that may result in the compromise of account credentials.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-16-350-02 | us government resource third party advisory mitigation |
http://www.securityfocus.com/bid/94937 | vdb entry third party advisory |