vendor:
Osprey Pump Controller
by:
LiquidWorm
7.5
CVSS
HIGH
Unauthenticated File Disclosure
284
CWE
Product Name: Osprey Pump Controller
Affected Version From: Software Build ID 20211018, Production 10/18/2021
Affected Version To: Mirage App: MirageAppManager, Release [1.0.1]
Patch Exists: No
Related CWE:
CPE: a:propump_and_controls:osprey_pump_controller:1.0.1
Platforms Tested:
2021
Osprey Pump Controller 1.0.1 – Unauthenticated File Disclosure
A vulnerability in ProPump and Controls' Osprey Pump Controller 1.0.1 allows an unauthenticated attacker to gain access to sensitive files without any authentication. This vulnerability is due to the lack of authentication protection in the system navigation. By exploiting this vulnerability, an attacker can gain access to all critical pump station information without any password protection.
Mitigation:
ProPump and Controls should implement authentication protection in the system navigation to prevent unauthenticated access to sensitive files.