CVE-2020-12496 Details
Description
Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) and Memograph M (Neutral/Private Label) (RSG45, ORSG45) with Firmware version V2.0.0 and above is prone to exposure of sensitive information to an unauthorized actor. The firmware release has a dynamic token for each request submitted to the server, which makes repeating requests and analysis complex enough. Nevertheless, it's possible and during the analysis it was discovered that it also has an issue with the access-control matrix on the server-side. It was found that a user with low rights can get information from endpoints that should not be available to this user.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.vde.com/en-us/advisories/vde-2020-022 | CVE | Vendor Advisory |
| https://cert.vde.com/en-us/advisories/vde-2020-022 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| endress rsg35 firmware | < 2.0.0 |
CPE
Remediation
| |
| endress rsg35 | All versions |
CPE
Remediation
| |
| endress rsg45 firmware | < 2.0.0 |
CPE
Remediation
| |
| endress rsg45 | All versions |
CPE
Remediation
| |
| endress orsg35 firmware | < 2.0.0 |
CPE
Remediation
| |
| endress orsg35 | All versions |
CPE
Remediation
| |
| endress orsg45 firmware | < 2.0.0 |
CPE
Remediation
| |
| endress orsg45 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 8, 2020 | Initial Analysis | [email protected] |