ID

VAR-201310-0721


TITLE

IBC Solar ServeMaster TLP+ 'setup_comm_smtp.tcl' has multiple information disclosure vulnerabilities

Trust: 0.6

sources: CNVD: CNVD-2013-13539

DESCRIPTION

IBC Solar ServeMaster TLP+ contains a security vulnerability in /cgi-bin/setup_comm_smtp.tcl that allows authentication credentials to be sent in clear text over HTTP, allowing an attacker to obtain SMTP server authentication information. IBC Solar ServeMaster TLP + is an inverter device for photovoltaic power generation system of IBC Solar, Germany. An information disclosure vulnerability exists in IBC Solar ServeMaster TLP +. Attackers can use this vulnerability to gain access to sensitive information by sniffing the network. Successful exploits will lead to other attacks

Trust: 1.35

sources: CNVD: CNVD-2013-13539 // CNNVD: CNNVD-201310-164 // BID: 62764

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-13539

AFFECTED PRODUCTS

vendor:ibcmodel:solar servemaster tlp+scope: - version: -

Trust: 0.6

vendor:ibcmodel:solar servemaster tlp+scope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2013-13539 // BID: 62764

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2013-13539
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2013-13539
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2013-13539

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201310-164

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201310-164

EXTERNAL IDS

db:BIDid:62764

Trust: 1.5

db:CNVDid:CNVD-2013-13539

Trust: 0.6

db:CNNVDid:CNNVD-201310-164

Trust: 0.6

sources: CNVD: CNVD-2013-13539 // BID: 62764 // CNNVD: CNNVD-201310-164

REFERENCES

url:http://dariusfreamon.wordpress.com/2013/10/01/ibc-solar-multiple-vulnerabilities/

Trust: 0.9

url:http://www.securityfocus.com/bid/62764

Trust: 0.6

url:http://www.ibc-solar.de/

Trust: 0.3

sources: CNVD: CNVD-2013-13539 // BID: 62764 // CNNVD: CNNVD-201310-164

CREDITS

Darius Freamon

Trust: 0.9

sources: BID: 62764 // CNNVD: CNNVD-201310-164

SOURCES

db:CNVDid:CNVD-2013-13539
db:BIDid:62764
db:CNNVDid:CNNVD-201310-164

LAST UPDATE DATE

2022-05-17T02:00:03.342000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-13539date:2013-10-10T00:00:00
db:BIDid:62764date:2013-10-01T00:00:00
db:CNNVDid:CNNVD-201310-164date:2013-10-12T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-13539date:2013-10-10T00:00:00
db:BIDid:62764date:2013-10-01T00:00:00
db:CNNVDid:CNNVD-201310-164date:2013-10-12T00:00:00