Intrusion Prevention

Meteocontrol.WEBlog.Information.Disclousre

Description

This indicates an attack attempt to exploit an Information Disclosure Vulnerability in Meteocontrol WEB'log.
The vulnerability is due to an design flaw in the vulnerable application when handling a request without authentication. An attacker can exploit this to disclose arbitrary files on the affected machine via an unauthenticated request.

Affected Products

Meteocontrol WEB'log Basic 100
Meteocontrol WEB'log Light
Meteocontrol WEB'log Pro
Meteocontrol WEB'log Pro Unlimited

Impact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

Recommended Actions

Apply the most recent upgrade or patch from the vendor:
https://us.meteocontrol.com/downloads/

CVE References

CVE-2016-2298 CVE-2016-2296

Other References

39822 ICSA-16-133-01