"value":"Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP addresses, usernames, store names and other sensitive information."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
"cweId":"CWE-200"
}
]
},
{
"description":[
{
"lang":"eng",
"value":"CWE-287 Improper Authentication",
"cweId":"CWE-287"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"Danfoss",
"product":{
"product_data":[
{
"product_name":"AK-SM800A",
"version":{
"version_data":[
{
"version_affected":"=",
"version_value":"< 3.3"
}
]
}
}
]
}
}
]
}
},
"references":{
"reference_data":[
{
"url":"https://csirt.divd.nl/CVE-2023-25913",
"refsource":"MISC",
"name":"https://csirt.divd.nl/CVE-2023-25913"
},
{
"url":"https://csirt.divd.nl/DIVD-2023-00025",
"refsource":"MISC",
"name":"https://csirt.divd.nl/DIVD-2023-00025"
}
]
},
"generator":{
"engine":"Vulnogram 0.1.0-dev"
},
"source":{
"discovery":"EXTERNAL"
},
"work_around":[
{
"lang":"en",
"supportingMedia":[
{
"base64":false,
"type":"text/html",
"value":"Upgrade to the latest patch, which is version 3.3."
}
],
"value":"Upgrade to the latest patch, which is version 3.3."