First published: Mon Dec 21 2015(Updated: )
Directory traversal vulnerability in the web server on Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allows remote attackers to bypass authentication, and write to a configuration file or trigger a calibration or test, via unspecified vectors.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Honeywell Midas Black Firmware | <=2.13b1 | |
Honeywell Midas Firmware | <=1.13b1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7907 is classified as a high severity vulnerability due to its potential for remote exploitation.
To mitigate CVE-2015-7907, users should update Honeywell Midas gas detectors to firmware versions 1.13b3 or 2.13b3 or later.
CVE-2015-7907 affects Honeywell Midas and Midas Black gas detectors running firmware versions prior to 1.13b3 and 2.13b3.
An attacker exploiting CVE-2015-7907 can bypass authentication and potentially modify configuration files or initiate calibration tests.
CVE-2015-7907 was disclosed in December 2015 as part of an advisory from the Industrial Control Systems Cyber Emergency Response Team.