← back
CVE-2014-2356

Innominate mGuard Exposure of Sensitive Information to an Unauthorized Actor

CVSS 4.3 EPSS 3.4%CWE-200
Innominate mGuard before 7.6.4 and 8.x before 8.0.3 does not require authentication for snapshot downloads, which allows remote attackers to obtain sensitive information via a crafted HTTPS request.
AV:N/AC:M/Au:N/C:P/I:N/A:N
Affected products
Innominate · mGuard

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →