CVE-2020-15794

A vulnerability has been identified in Desigo Insight (All versions). Some error messages in the web application show the absolute path to the requested resource. This could allow an authenticated attacker to retrieve additional information about the host system.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:desigo_insight:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:desigo_insight:6.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:desigo_insight:6.0:sp2:*:*:*:*:*:*
cpe:2.3:a:siemens:desigo_insight:6.0:sp3:*:*:*:*:*:*
cpe:2.3:a:siemens:desigo_insight:6.0:sp5:*:*:*:*:*:*

History

18 Nov 2021, 17:00

Type Values Removed Values Added
CWE CWE-200 CWE-209
References (MISC) https://us-cert.cisa.gov/ics/advisories/icsa-20-287-05 - (MISC) https://us-cert.cisa.gov/ics/advisories/icsa-20-287-05 - Third Party Advisory, US Government Resource

Information

Published : 2020-10-15 19:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-15794

Mitre link : CVE-2020-15794

CVE.ORG link : CVE-2020-15794


JSON object : View

Products Affected

siemens

  • desigo_insight
CWE
CWE-209

Generation of Error Message Containing Sensitive Information

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor