.. / CVE-2019-15859

Exploit for Socomec DIRIS A-40 Devices Password Disclosure (CVE-2019-15859)

Description:

Socomec DIRIS A-40 devices before 48250501 are susceptible to a password disclosure vulnerability in the web interface that could allow remote attackers to get full access to a device via the /password.jsn URI.

Nuclei Template

View the template here CVE-2019-15859.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2019/CVE-2019-15859.yaml
Copy

References:

https://seclists.org/fulldisclosure/2019/Oct/10
http://seclists.org/fulldisclosure/2019/Oct/10
http://packetstormsecurity.com/files/154764/Socomec-DIRIS-A-40-Password-Disclosure.html
https://nvd.nist.gov/vuln/detail/CVE-2019-15859
https://www.socomec.com/single-circuit-multifunction-meters_en.html