In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can access an alternative configuration page config_main.php that allows manipulation of the device.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://applied-risk.com/labs/advisories | third party advisory |
https://ics-cert.us-cert.gov/advisories/ICSA-19-078-02 | third party advisory us government resource |