9.8
CVSSv3

CVE-2019-11367

Published: 03/06/2019 Updated: 24/08/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in AUO Solar Data Recorder prior to 1.3.0. The web portal uses HTTP Basic Authentication and provides the account and password in the WWW-Authenticate attribute. By using this account and password, anyone can login successfully.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

auo solar data recorder

Exploits

AUO Solar Data Recorder versions prior to 130 suffer from an incorrect access control vulnerability ...