S4E just found a critical-severity finding from cve-2022-27924 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jul 15, 2024

CVE-2024-5947 Scanner

CVE-2024-5947 scanner - Information Disclosure vulnerability in Deep Sea Electronics DSE855

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-5947
6.5
CVSSmedium
Exploitable from an adjacent network · no authentication required.

Deep Sea Electronics DSE855 Configuration Backup Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based UI. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-22679.

Attack Vector
Adjacent
Privileges Req.
None
User Interaction
None
Affected
DSE855by Deep Sea Electronics
1.1.0
Updated Sep 10, 2026View on NVD →
Detail

Deep Sea Electronics DSE855 is widely used in industrial and commercial settings for power generation control. It is commonly implemented by facility managers and technicians to ensure seamless operation of power systems. The device offers remote monitoring and control capabilities via a web-based UI. It is designed to support critical power infrastructure in diverse environments. Users depend on the DSE855 for reliable and secure power management solutions.

The DSE855 has a vulnerability that allows attackers to bypass authentication mechanisms. This flaw exists in the web-based UI of the device. An attacker can exploit this vulnerability to access sensitive information without needing to authenticate. This can lead to disclosure of stored credentials and other sensitive data.

The vulnerability is found in the web-based user interface of the DSE855. Specifically, the issue is due to the lack of authentication required to access the configuration backup functionality. Attackers can send a request to download the backup file (Backup.bin) without authenticating. The downloaded file can contain sensitive information such as stored credentials. This flaw is exploited by sending crafted HTTP requests to the device.

Exploiting this vulnerability can lead to unauthorized access to sensitive information. Attackers may obtain stored credentials, enabling further unauthorized access to the device and network. This can compromise the security of the entire power management system. Additionally, it can lead to potential manipulation or disruption of power control operations.

Join S4E to ensure the security of your digital assets with our comprehensive cyber threat exposure management services. Our platform offers advanced scanning capabilities to detect and report vulnerabilities in your systems. Benefit from detailed reports, expert recommendations, and continuous monitoring to safeguard your infrastructure. Stay ahead of potential threats and protect your organization's critical operations. Sign up now to enhance your cybersecurity posture with S4E.

References:

Solution Advice
  • Implement proper authentication mechanisms for accessing the web-based UI.
  • Regularly update and patch the device firmware to address known vulnerabilities.
  • Limit network access to the device to trusted users and networks only.
  • Monitor and log access to the device for any unauthorized attempts.
  • Educate and train staff on security best practices and vulnerability management.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.