Automated Logic WebCTRL
cpe:2.3:a:automatedlogic:webctrl:*:*:*:*:*:*:*, +1 more
- <= 8.5
A vulnerability allowing access control bypass has been identified in ALC WebCTRL and Carrier i-Vu, in versions up to and including 8.5. This vulnerability enables a malicious actor to circumvent intended access restrictions and access sensitive information through the web-based building automation server.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information via the web-based building automation server.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.