SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-10243

In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies.

MEDIUM 5.3EPSS 1.34%

Does this matter?

Lower severity and a low EPSS score (1.34%). Track it; it rarely justifies an emergency change on its own.

Description

In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies. This can be used as a hint by an attacker to specifically craft attacks to the web server run by Kura.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
1.34% probability · 70th percentile
CISA KEV
Not listed
Weakness
CWE-497, CWE-200
Affected
eclipse/kura
Source
emo@eclipse.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.