CVE-2021-23195 Information
Jun 07, 2022
cve
Description
Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 has the option for automated indexing (directory listing) activated. When accessing a directory a web server delivers its entire content in HTML form. If an index file does not exist and directory listing is enabled all content of the directory will be displayed allowing an attacker to identify and access files on the server.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
https://www.cisa.gov/uscert/ics/advisories/icsma-21-355-01
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: