ZeroHour

CVE-2022-47554

CVSS 3.1
7.5 high
EPSS
<1%p48
Published
()
Modified
Description

Exposure of sensitive information in ekorCCP and ekorRCI, potentially allowing a remote attacker to obtain critical information from various .xml files, including .xml files containing credentials, without being authenticated within the web server.

Vendors
ormazabal
Products
ekorrci firmware, ekorccp firmware
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.