Cleartext HTTP Vulnerability in MOBOTIX S14 Management Application
CVE-2019-7675

7.5HIGH

Key Information:

Vendor

Mobotix

Vendor
CVE Published:
9 February 2019

What is CVE-2019-7675?

A vulnerability has been discovered in MOBOTIX S14 devices that affects the default management application, which is exposed over cleartext HTTP. This flaw enables unauthorized access as it utilizes Basic Authentication, allowing potential attackers to intercept sensitive data transmitted through the /admin/index.html URI without encryption. Proper measures should be taken to ensure secure communication and protect against exploitation.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.