CVE-2020-15790
09.09.2020, 19:15
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). If configured in an insecure manner, the web server might be susceptible to a directory listing attack.Enginsight
Vendor | Product | Version |
---|---|---|
siemens | spectrum_power_4 | 𝑥 < 4.70 |
siemens | spectrum_power_4 | 4.70 |
siemens | spectrum_power_4 | 4.70:sp7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-548 - Exposure of Information Through Directory ListingA directory listing is inappropriately exposed, yielding potentially sensitive information to attackers.
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.