CVE-2023-39467
MEDIUMDescription
Triangle MicroWorks SCADA Data Gateway certificate Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of certificate web directory. The issue results from the exposure of sensitive information in the application webroot. An attacker can leverage this vulnerability to disclose sensitive information. Was ZDI-CAN-20798.
Is your site exposed to CVE-2023-39467?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| trianglemicroworks | scada_data_gateway |
References
Frequently Asked Questions
What is CVE-2023-39467? +
How severe is CVE-2023-39467? +
What products are affected by CVE-2023-39467? +
How do I check if I'm vulnerable to CVE-2023-39467? +
Related Vulnerabilities
Avtec Outpost stores sensitive information in an insecure location without proper access controls in place.
Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated user to read …
Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of …
Triangle MicroWorks SCADA Data Gateway Restore Workspace Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute …
Triangle MicroWorks SCADA Data Gateway Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files …
Triangle MicroWorks SCADA Data Gateway Use of Hard-coded Cryptograhic Key Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose …