CVE-2020-15794
Summary
| CVE | CVE-2020-15794 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-15 19:15:00 UTC |
| Updated | 2021-11-18 17:00:00 UTC |
| Description | A vulnerability has been identified in Desigo Insight (All versions). Some error messages in the web application show the absolute path to the requested resource. This could allow an authenticated attacker to retrieve additional information about the host system. |
Risk And Classification
Problem Types: CWE-209
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Siemens | Desigo Insight | All | All | All | All |
| Application | Siemens | Desigo Insight | 6.0 | - | All | All |
| Application | Siemens | Desigo Insight | 6.0 | sp2 | All | All |
| Application | Siemens | Desigo Insight | 6.0 | sp3 | All | All |
| Application | Siemens | Desigo Insight | 6.0 | sp5 | All | All |
| Application | Siemens | Desigo Insight | All | All | All | All |
| Application | Siemens | Desigo Insight | 6.0 | - | All | All |
| Application | Siemens | Desigo Insight | 6.0 | sp2 | All | All |
| Application | Siemens | Desigo Insight | 6.0 | sp3 | All | All |
| Application | Siemens | Desigo Insight | 6.0 | sp5 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Siemens Desigo Insight | CISA | MISC | us-cert.cisa.gov | |
| cert-portal.siemens.com/productcert/pdf/ssa-226339.pdf | MISC | cert-portal.siemens.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.