An issue was discovered in OmniMetrix OmniView, Version 1.2. Insufficient password requirements for the OmniView web application may allow an attacker to gain access by brute forcing account passwords.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-16-350-02 | us government resource third party advisory mitigation |
http://www.securityfocus.com/bid/94937 | vdb entry third party advisory |