First published: Fri Jan 15 2016(Updated: )
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows remote attackers to discover credentials by reading detailed error messages.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Web Viewer | <=1.0.0.193 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8280 has a medium severity rating due to its potential to expose sensitive credentials.
To fix CVE-2015-8280, update the Samsung Web Viewer to a version above 1.0.0.193.
CVE-2015-8280 affects Samsung SRN-1670D devices running Web Viewer version 1.0.0.193 or earlier.
CVE-2015-8280 enables remote attackers to discover user credentials through detailed error messages.
A possible workaround for CVE-2015-8280 is to disable detailed error messages in the configuration.