Summary:

Directory traversal vulnerability in the web server on Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allows remote attackers to bypass authentication, and write to a configuration file or trigger a calibration or test, via unspecified vectors.

Reference Links(if available):

  • https://ics-cert.us-cert.gov/advisories/ICSA-15-309-02
  • CVSS Score (if available)

    v2: / HIGHAV:N/AC:L/Au:N/C:N/I:P/A:P

    v3: / HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L

    Links to Exploits(if available)

  • By admin