CVE-2020-12495
Published: Nov 19, 2020
Modified: Sep 16, 2024
CVSS v3.1
9.1
Description
Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management. The affected device has a web-based user interface with a role-based access system. Users with different roles have different write and read privileges. The access system is based on dynamic "tokens". The vulnerability is that user sessions are not closed correctly and a user with fewer rights is assigned the higher rights when he logs on.
| Vendor | Product | Versions |
|---|---|---|
Endress+Hauser | RSG35 - Ecograph T | affected V1.0.0 - < V2.0.0 |
Endress+Hauser | ORSG35 - Ecograph T Neutral/Private Label | affected V1.0.0 - < V2.0.0 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now