CVE-2018-20220
21.03.2019, 16:00
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authentication before it can be interacted with, a large portion of the HTTP endpoints are missing authentication. An attacker is able to view these pages before being authenticated, and some of these pages may disclose sensitive information.Enginsight
Vendor | Product | Version |
---|---|---|
teracue | enc-400_hdmi_firmware | 𝑥 ≤ 2.56 |
teracue | enc-400_hdmi2_firmware | 𝑥 ≤ 2.56 |
teracue | enc-400_hdsdi_firmware | 𝑥 ≤ 2.56 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References