Directory traversal vulnerability in the web server on Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allows remote attackers to bypass authentication, and write to a configuration file or trigger a calibration or test, via unspecified vectors.
Reference Links(if available):
CVSS Score (if available)
v2: / HIGHAV:N/AC:L/Au:N/C:N/I:P/A:P
v3: / HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L