PatchSiren

Omnimetrix CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Omnimetrix CVE published 2017-02-13

CVE-2016-5801

CVE-2016-5801 affects OmniMetrix OmniView 1.2. The NVD description says insufficient password requirements in the OmniView web application may allow an attacker to gain access by brute forcing account passwords. NVD rates the issue CVSS 3.0 7.5/High and maps it to CWE-284 (Improper Access Control).

HIGH Omnimetrix CVE published 2017-02-13

CVE-2016-5786

CVE-2016-5786 is an information disclosure issue in OmniMetrix OmniView version 1.2. The web application transmits credentials using HTTP rather than an encrypted transport, which means an attacker able to observe the network path could capture those credentials and potentially compromise accounts. NVD lists the issue as HIGH severity with a CVSS 3.0 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N.