756
VMScore

CVE-2019-16261

Published: 12/09/2019 Updated: 13/09/2019
CVSS v2 Base Score: 8.5 | Impact Score: 7.8 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 756
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:C

Vulnerability Summary

Tripp Lite PDUMH15AT 12.04.0053 devices allow unauthenticated POST requests to the /Forms/ directory, as demonstrated by changing the manager or admin password, or shutting off power to an outlet. NOTE: the vendor's position is that a newer firmware version, fixing this vulnerability, had already been released before this vulnerability report about 12.04.0053.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tripplite pdumh15at_firmware 12.04.0053