CVE-2015-3943: Infoleak
Published Jan 15, 2016
·Updated
Advantech WebAccess before 8.1 allows remote attackers to read sensitive cleartext information about e-mail project accounts via unspecified vectors.
Affected Software
1 affected component
Advantech WebAccess<=8.0
Event History
Jan 15, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3943?
CVE-2015-3943 has been rated with a high severity due to its potential to expose sensitive information.
2
How do I fix CVE-2015-3943?
To mitigate CVE-2015-3943, upgrade Advantech WebAccess to version 8.1 or later where the vulnerability is resolved.
3
What type of information can be leaked by CVE-2015-3943?
CVE-2015-3943 allows remote attackers to read sensitive cleartext information about e-mail project accounts.
4
What versions of Advantech WebAccess are affected by CVE-2015-3943?
Advantech WebAccess versions prior to 8.1 are affected by CVE-2015-3943.
5
Is there a workaround for CVE-2015-3943?
While upgrading is the recommended approach, implement network segmentation and access controls to limit exposure.