First published: Mon Dec 21 2015(Updated: )
Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allow remote attackers to discover cleartext passwords by sniffing the network.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Honeywell Midas Firmware | <=1.13b1 | |
Honeywell Midas | ||
Honeywell Midas Black Firmware | <=2.13b1 | |
Honeywell Midas Black |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7908 has a medium severity rating due to the potential for remote attackers to intercept sensitive information.
To mitigate CVE-2015-7908, upgrade to Honeywell Midas firmware version 1.13b3 or later, and Midas Black firmware version 2.13b3 or later.
CVE-2015-7908 can be exploited through network sniffing to capture cleartext passwords.
Affected versions for CVE-2015-7908 include Honeywell Midas firmware prior to 1.13b3 and Midas Black firmware prior to 2.13b3.
Organizations using vulnerable Honeywell Midas and Midas Black gas detectors are at risk of password disclosure.