A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The handling of log files in the web application of affected devices contains an information disclosure vulnerability which could allow logged in users to access sensitive files.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-252466.pdf | patch vendor advisory |