CVE detail
CVE-2001-1341
The Beck GmbH IPC@Chip embedded web server installs the chipcfg.cgi program by default, which allows remote attackers to obtain sensitive network information via a request to the program.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 6.9 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
1 source links · newest first
Researchers at IT security services company SEC Consult have discovered several potentially serious vulnerabilities in solar park monitoring systems from Solar-Log. The vendor has released a firmware update to patch the flaws. Solare Datensysteme’s Solar-Log was recently named the largest vendor for residential and commercial photovoltaic (PV) monitoring. The company says its products have been used to monitor more than 260,000 solar plants worldwide. An advisory published on Wednesday by SEC Consult shows that the firm has identified a total of seven vulnerabilities. The security holes have been discovered after testing Solar-Log 1200 devices running firmware version 3.5.2-85 and Solar-Log 800e with firmware version 2.8.4-56. Other models are likely also affected considering that they use the same firmware. SEC Consult told SecurityWeek it has identified tens of thousands of potentially vulnerable devices that can be reached directly from the Internet. The security holes include an i…
newswww.securityweek.comMar 22, 2017, 11:48 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
3 related CVEs with shared weakness or product evidence
- CVE-2001-0749CVSS 7.5 · High
Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to read arbitrary files via a webserver root directory set to system root.
- CVE-2001-1428CVSS 7.5 · High
The (1) FTP and (2) Telnet services in Beck GmbH IPC@Chip are shipped with a default password, which allows remote attackers to gain unauthorized access.
- CVE-2001-1337CVSS 5.0 · Medium
Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to cause a denial of service via a long HTTP request.