CVE-2019-5616
Summary
| CVE | CVE-2019-5616 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-15 21:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | CircuitWerkes Sicon-8, a hardware device used for managing electrical devices, ships with a web-based front-end controller and implements an authentication mechanism in JavaScript that is run in the context of a user's web browser. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Broadcastboxes | Scion-8 | - | All | All | All |
| Hardware | Broadcastboxes | Scion-8 | - | All | All | All |
| Operating System | Broadcastboxes | Scion-8 Firmware | - | All | All | All |
| Operating System | Broadcastboxes | Scion-8 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CircuitWerkes Sicon-8 Client-Side Authentication Bypass Vuln Explained | MISC | blog.rapid7.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: This issue was discovered and reported by independent researcher Ph055a, and was validated and disclosed by Rapid7's Coordinated Vulnerability Disclosure program.
There are currently no legacy QID mappings associated with this CVE.