CVE-2020-21994
28.04.2021, 15:15
AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a successful authentication bypass attack.Enginsight
Vendor | Product | Version |
---|---|---|
ave | dominaplus | 1.10.11 ≤ 𝑥 ≤ 1.10.77 |
ave | 53ab-wbs_firmware | 1.10.62 |
ave | ts01_firmware | 1.0.65 |
ave | ts03x-v_firmware | 1.10.45a:a |
ave | ts04x-v_firmware | 1.10.45a:a |
ave | ts05_firmware | 1.10.36 |
ave | ts05n-v_firmware | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References