An issue was discovered in OmniMetrix OmniView, Version 1.2. The OmniView web application transmits credentials with the HTTP protocol, which could be sniffed by an attacker that may result in the compromise of account credentials.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/94937 | VDB Entry Third Party Advisory |
https://ics-cert.us-cert.gov/advisories/ICSA-16-350-02 | Mitigation Third Party Advisory US Government Resource |
Configurations
History
No history.
Information
Published : 2017-02-13 21:59
Updated : 2024-02-04 19:11
NVD link : CVE-2016-5786
Mitre link : CVE-2016-5786
CVE.ORG link : CVE-2016-5786
JSON object : View
Products Affected
omnimetrix
- omniview
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor