A security issue exists within the 5032 16pt Digital Configurable module’s web server. Intercepted session credentials can be used within a 3-minute timeout window, allowing unauthorized users to perform privileged actions.
Solution:
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.