First published: Sat Jan 18 2020(Updated: )
Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different functions of the web application via requests that lack certain mandatory parameters. This affects ifaces-diag.asp, system.asp, backup.asp, sys-power.asp, ifaces-wls.asp, ifaces-wls-pkt.asp, and ifaces-wls-pkt-adv.asp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Westermo Mrd-315 Firmware | =1.7.3 | |
Westermo Mrd-315 Firmware | =1.7.4 | |
Westermo MRD-315 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the information disclosure vulnerability in Westermo MRD-315 devices is CVE-2020-7227.
The affected software versions for the information disclosure vulnerability in Westermo MRD-315 devices are 1.7.3 and 1.7.4.
The information disclosure vulnerability in Westermo MRD-315 devices allows an authenticated remote attacker to retrieve the source code of different functions of the web application via requests that lack certain mandatory parameters.
The severity of CVE-2020-7227 is medium with a CVSS score of 6.5.
To fix the information disclosure vulnerability in Westermo MRD-315 devices, it is recommended to update to a patched version of the firmware provided by Westermo.