ID

VAR-202103-1794


TITLE

Huafu Kaiwu controX has an information disclosure vulnerability

Trust: 0.6

sources: CNVD: CNVD-2021-07488

DESCRIPTION

The controX (Huafu Kaiwu) series of industrial configuration software is a cross-platform general-purpose operating system for the next generation of operating systems developed by Beijing Huafu Yuanke Technology Co., Ltd. after years of development in full integration of user needs and the latest development direction in the field of industrial automation Configuration platform software products. Huafu Kaiwu controX has an information disclosure vulnerability. Attackers can use vulnerabilities to obtain sensitive information.

Trust: 0.6

sources: CNVD: CNVD-2021-07488

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-07488

AFFECTED PRODUCTS

vendor:huafu yuankemodel:controxscope:eqversion:3.0.18

Trust: 0.6

sources: CNVD: CNVD-2021-07488

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2021-07488
value: LOW

Trust: 0.6

CNVD: CNVD-2021-07488
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2021-07488

EXTERNAL IDS

db:CNVDid:CNVD-2021-07488

Trust: 0.6

sources: CNVD: CNVD-2021-07488

SOURCES

db:CNVDid:CNVD-2021-07488

LAST UPDATE DATE

2022-05-04T08:52:10.782000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-07488date:2021-02-03T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-07488date:2021-03-01T00:00:00