Description
Information disclosure vulnerability in error handling in MiR software prior to version 3.0.0 allows unauthenticated attackers to view detailed error information, such as file paths and other data, via access to verbose error pages.
Problem types
CWE-209 Generation of Error Message Containing Sensitive Information
Product status
Any version before 3.0.0
Any version before 3.0.0
Credits
Lockheed Martin Red Team
References
a.storyblok.com/f/230581/x/34a075d078/msa-17.pdf
supportportal.mobile-industrial-robots.com/...ecurity-guide/