Description
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, exposes web-accessible file paths that are not protected by an authorization scheme. An unauthenticated attacker can directly access HTTP endpoints to download files from locations such as /Resources/CompanyId_[ID]/Audio/ and /SafeData/.
Problem types
CWE-425 Direct request ('forced browsing')
Product status
Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014
Credits
Christian Hager, SEC Consult Vulnerability Lab
Gorazd Jank, SEC Consult Vulnerability Lab
Philipp Espernberger, SEC Consult Vulnerability Lab
References
wertheim-safes.com/safe-deposit-box-management/
r.sec-consult.com/wertheim