IBC Solar ServeMaster Source Code Vulnerability (CVE-2015-6469)
IBC Solar ServeMaster Source Code Vulnerability (CVE-2015-6469)
Release date:
Updated on:
Affected Systems:
IBC Solar ServeMaster TLP +
IBC Solar Danfoss TLX Pro +
Description:
CVE (CAN) ID: CVE-2015-6469
ServeMaster TLP + and Danfoss TLX Pro + are Web-based SCADA systems.
Due to incorrect interpreter settings, attackers can exploit this vulnerability to obtain the source code of executable scripts.
<* Source: Maxim Rupp
*>
Suggestion:
Vendor patch:
IBC Solar
---------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Https://www.ibc-solar.com/
Https://www.nsa.gov/ia/_files/factsheets/xss_iad_factsheet_final_web.pdf
This article permanently updates the link address: