ZeroHour

CVE-2019-11367

PoC ×3
CVSS 3.0
9.8 critical
EPSS
3%p86
Published
()
Modified
Description

An issue was discovered in AUO Solar Data Recorder before 1.3.0. The web portal uses HTTP Basic Authentication and provides the account and password in the WWW-Authenticate attribute. By using this account and password, anyone can login successfully.

Vendors
auo
Products
solar data recorder
Weakness
CWE-311, CWE-522
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.