VulnerabilityModified
CVE-2015-5671
Techno Project Japan Enisys Gw before 1.4.1 allows remote attackers to bypass intended access restrictions and read arbitrary uploaded files via unspecified vectors.
MEDIUM 5.0EPSS 1.42%
Does this matter?
Lower severity and a low EPSS score (1.42%). Track it; it rarely justifies an emergency change on its own.
Description
Techno Project Japan Enisys Gw before 1.4.1 allows remote attackers to bypass intended access restrictions and read arbitrary uploaded files via unspecified vectors.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.42% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- techno project japan/enisys gw
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN68289108/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000170Vendor Advisory
- http://www.tpj.co.jp/enisys/resource.htmlVendor Advisory
- http://jvn.jp/en/jp/JVN68289108/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000170Vendor Advisory
- http://www.tpj.co.jp/enisys/resource.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.