CVE-2019-16261 Information
Feb 14, 2021
cve
Description
Tripp Lite PDUMH15AT 12.04.0053 devices allow unauthenticated POST requests to the /Forms/ directory as demonstrated by changing the manager or admin password or shutting off power to an outlet. NOTE: the vendor’s position is that a newer firmware version fixing this vulnerability had already been released before this vulnerability report about 12.04.0053.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Reference
https://blog.korelogic.com/blog/2019/08/19/unpatched_fringe_infrastructure_bits
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.1
Share on: