peter bassill · operator
$ cve CVE-2015-7902 JSON

CVE-2015-7902 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 3.5% (pctl 89)

Patch early

A public exploit exists.

Description

Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 provides different error messages for failed login attempts in unspecified circumstances, which allows remote attackers to obtain sensitive information via a series of requests.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS3.5% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2015-10-28
Last modified2026-06-17

Affected (1)

VendorProduct
infinite automation systemsmango automation

Public exploits

SourceTitleDate
exploit-dbMango Automation 2.6.0 - Multiple Vulnerabilities2015-09-28

References

→ the Explorer  ·  watch your stack  ·  NVD