Lucene search

K
cve[email protected]CVE-2019-12183
HistoryMar 02, 2020 - 4:15 p.m.

CVE-2019-12183

2020-03-0216:15:11
CWE-269
web.nvd.nist.gov
19
cve-2019-12183
incorrect access control
safescan timemoto
tm-616
ta-8000
remote attack
administrative api

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.5 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

75.9%

Incorrect Access Control in Safescan Timemoto TM-616 and TA-8000 series allows remote attackers to read any file via the administrative API.

Affected configurations

NVD
Node
safescantimemoto_tm-616Match-
AND
safescantimemoto_tm-616_firmwareMatch-
Node
safescanta-8035Match-
AND
safescanta-8035_firmwareMatch-
Node
safescanta-8010Match-
AND
safescanta-8010_firmwareMatch-
Node
safescanta-8015Match-
AND
safescanta-8015_firmwareMatch-
Node
safescanta-8020Match-
AND
safescanta-8020_firmwareMatch-
Node
safescanta-8025Match-
AND
safescanta-8025_firmwareMatch-
Node
safescanta-8030Match-
AND
safescanta-8030_firmwareMatch-

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.5 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

75.9%

Related for CVE-2019-12183