Home

Description

HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of the webservices used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It unnecessarily exposes sensitive information about the server configuration.

PUBLISHED Reserved 2026-01-30 | Published 2026-02-26 | Updated 2026-02-26 | Assigner arcinfo




LOW: 2.3CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/AU:Y/R:U/RE:M/U:Clear

Problem types

CWE-201 Insertion of Sensitive Information into Sent Data

Product status

Default status
unaffected

16.0.0 (cpe)
affected

15.0.0 (cpe)
affected

12.0.0 (cpe)
affected

References

www.pcvue.com/security/ vendor-advisory

cve.org (CVE-2026-1694)

nvd.nist.gov (CVE-2026-1694)

Download JSON