Tibbo AggreGate Network Manager
cpe:2.3:a:tibbo:aggregate:*:*:*:*:*:*:*
- < 6.40.05
A vulnerability exists in Tibbo AggreGate Network Manager versions prior to 6.40.05, where sensitive system information is exposed through an unauthenticated endpoint. The affected endpoint, /cwmp/happyaxis.jsp, discloses Java system properties, server path details, and version information to unauthorized users. This information leakage could potentially be exploited to facilitate further attacks on the system.
The vulnerability allows unauthorized users to access sensitive system information, which could be used to compromise the system further.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.