CVE-2017-14013 Information
Feb 14, 2021
cve
Description
A Client-Side Enforcement of Server-Side Security issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The log out function in the application removes the user’s session only on the client side. This may allow an attacker to bypass protection mechanisms gain privileges or assume the identity of an authenticated user.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Reference
http://www.securityfocus.com/bid/101259 https://ics-cert.us-cert.gov/advisories/ICSA-17-285-01
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
LOW
Base Severity
5.6
Share on: