A vulnerability has been identified in Desigo Insight (All versions). Some error messages in the web application show the absolute path to the requested resource. This could allow an authenticated attacker to retrieve additional information about the host system.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Link | Tags |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-226339.pdf | vendor advisory |
https://us-cert.cisa.gov/ics/advisories/icsa-20-287-05 | third party advisory us government resource |