Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing the /deviceIP information, which leads to internal network information disclosure.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://sadfud.me/explotos/deviceip.txt | third party advisory exploit |
https://www.exploit-db.com/exploits/44488/ | exploit vdb entry third party advisory |