Description
Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially resulting in unintended access to protected data.
Problem types
CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory
Product status
100.1 (cpe)
Credits
Andreas Krämer, BASF Digital Solutions GmbH
Martin Floeck, BASF Digital Solutions GmbH
Stefan Stahl, BASF Digital Solutions GmbH
References
process.honeywell.com/