A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with network access to the TeleControl Server Basic's port 8000/tcp could bypass the authentication mechanism and read limited information.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-651454.pdf | patch vendor advisory |
http://www.securityfocus.com/bid/102894 | third party advisory vdb entry |
http://www.securityfocus.com/bid/102904 | third party advisory vdb entry |