7.5
CVSSv2

CVE-2016-2296

Published: 14/05/2016 Updated: 07/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.4 | Impact Score: 5.5 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remote malicious users to obtain sensitive information or modify data via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

meteocontrol web\\'log pro unlimited -

meteocontrol web\\'log pro -

meteocontrol web\\'log light -

meteocontrol web\\'log basic 100 -

Exploits

# Exploit Title: [Meteocontrol WEB'log - Extract Admin password] # Discovered by: Karn Ganeshen # Vendor Homepage: [wwwmeteocontrolcom/en/] # Versions Reported: [All Meteocontrol WEB'log versions] # CVE-ID: [CVE-2016-2296] # Meteocontrol WEB'log - Metasploit Auxiliary Module [modules/auxiliary/admin/scada/meteocontrol_weblog_loginrb] # ...
This Metasploit module exploits an authentication bypass vulnerability in Meteocontrol WEBLog (all models) This vulnerability allows extracting Administrator password for the device management portal ...