CVE Database
/

CVE-2019-6837

Back to search

CVE-2019-6837

Published: Sep 17, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

A Server-Side Request Forgery (SSRF): CWE-918 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could cause server configuration data to be exposed when an attacker modifies a URL.

VendorProductVersions

CVE-2019-6837

U.motion Server

affected
MEG6501-0001 - U.motion KNX server
affected
MEG6501-0002 - U.motion KNX Server Plus
affected
MEG6260-0410 - U.motion KNX Server Plus
affected
Touch 10
affected
MEG6260-0415 - U.motion KNX Server Plus

+1 more versions

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now