Vulnerabilities > CVE-2013-3505 - Credentials Management vulnerability in Gwos Groundwork Monitor 6.7.0

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
gwos
CWE-255

Summary

The Nagios-App component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to bypass intended access restrictions via a direct request for a (1) log file or (2) configuration file.

Vulnerable Configurations

Part Description Count
Application
Gwos
1

Common Weakness Enumeration (CWE)