vendor:
WebVersion
by:
t4rkd3vilz
8.8
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: WebVersion
Affected Version From: 3.2.1.294365
Affected Version To: 3.3.37.274972
Patch Exists: NO
Related CWE: N/A
CPE: a:honeywell:webversion:3.2.1.294365
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2018
Honeywell Scada System – Information Disclosure
An attacker can download a file containing critical information about the destination address by accessing the URL https://TargetIp/web_caps/webCapsConfig
Mitigation:
Restrict access to the URL https://TargetIp/web_caps/webCapsConfig and ensure that only authorized personnel have access to the file.