Socomec DIRIS A-40 devices before 48250501 are susceptible to a password disclosure vulnerability in the web interface that could allow remote attackers to get full access to a device via the /password.jsn URI.
View the template here CVE-2019-15859.yaml
References:
https://seclists.org/fulldisclosure/2019/Oct/10