"value":"The webreport generation feature in the Danfoss AK-EM100 allows an unauthorized actor to generate a web report that discloses sensitive information such as the internal IP address, usernames and internal device values."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
"cweId":"CWE-200"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"Danfoss",
"product":{
"product_data":[
{
"product_name":"AK-EM100",
"version":{
"version_data":[
{
"version_affected":"<=",
"version_name":"< 2.2.0.12",
"version_value":" 2.2.0.12"
}
]
}
}
]
}
}
]
}
},
"references":{
"reference_data":[
{
"url":"https://divd.nl/cves/CVE-2023-25912",
"refsource":"MISC",
"name":"https://divd.nl/cves/CVE-2023-25912"
},
{
"url":"https://csirt.divd.nl/DIVD-2023-00021",
"refsource":"MISC",
"name":"https://csirt.divd.nl/DIVD-2023-00021"
}
]
},
"generator":{
"engine":"Vulnogram 0.1.0-dev"
},
"source":{
"discovery":"EXTERNAL"
},
"work_around":[
{
"lang":"en",
"value":"The AK-EM100 has been declared End of Life (EOL). Danfoss advises phasing out this type of device.",
"supportingMedia":[
{
"type":"text/html",
"base64":false,
"value":"The AK-EM100 has been declared End of Life (EOL). Danfoss advises phasing out this type of device."