S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-15859 Scanner

CVE-2019-15859 scanner - Information Disclosure vulnerability in Socomec DIRIS A-40

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-15859
9.8
CVSS

Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the /password.jsn URI.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Socomec DIRIS A-40 is an advanced power meter that is widely used in commercial and industrial applications. It is well-known for its advanced measurement capabilities and ability to collect and measure data in real-time. The device is designed to provide accurate and reliable data on energy consumption, power quality, and overall energy efficiency. The device has a web interface that allows users to make configuration changes and access data remotely.

The CVE-2019-15859 vulnerability is a serious security flaw that has been detected in the Socomec DIRIS A-40 device. This vulnerability allows remote attackers to gain full access to the device, simply by using the /password.jsn URI. This essentially means that an attacker can take full control of the device, including access to sensitive data, critical configurations, and the ability to make unauthorized changes.

If the CVE-2019-15859 vulnerability is exploited, it can have several dangerous consequences for the affected device. An attacker can gain unauthorized access to sensitive information, disable critical systems, or even cause physical damage to the device. This type of vulnerability can also allow an attacker to gain access to other devices connected to the same network, compounding the potential impact of such an exploit.

In conclusion, vulnerability such as CVE-2019-15859 in devices like the Socomec DIRIS A-40 can pose a huge risk to organizations and individuals. It is crucial to take appropriate measures to address and prevent such vulnerabilities. By leveraging the pro features of the s4e.io platform, readers can easily and quickly learn about vulnerabilities in their digital assets, and take appropriate action to protect against them.

 

REFERENCES

Solution Advice

To protect against CVE-2019-15859, individuals and organizations using Socomec DIRIS A-40 devices are advised to take the following precautions:

  • Update the device firmware to the latest version as soon as possible.
  • Restrict access to the web interface of the device only to authorized personnel.
  • Implement strong passwords and two-factor authentication to protect login credentials.
  • Monitor network traffic to detect any attempts to exploit this vulnerability.
  • Use an intrusion detection system (IDS) or monitoring tool to detect any suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-15859 scanner - Information Disclosure vulnerability in Socomec DIRIS A-40 | S4E