CVE-2004-2317Software Mbedthis Appweb Http Server vulnerability

3 documents3 sources
Severity
5.0MEDIUMNVD
EPSS
0.3%
top 46.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 31
Latest updateApr 29

Description

Information leak in Mbedthis AppWeb HTTP server 1.0 through 1.1.2 allows remote attackers to obtain sensitive information via a user message that is generated when Mbedthis denies access.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-v76h-x8gq-77v4: Information leak in Mbedthis AppWeb HTTP server 12022-04-29
CVEList
CVE-2004-2317: Information leak in Mbedthis AppWeb HTTP server 12005-08-16
CVE-2004-2317 — MEDIUM severity | cvebase