VendorsLAN ATMservicem3_atm_monitoring_systemall versions
Vulnerabilities

LAN ATMservice M3 ATM Monitoring System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2020-29667
In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.
Published 2020-12-10 · Modified
10.0EPSS 0.032
CVE-2020-29666
In Lan ATMService M3 ATM Monitoring System 6.1.0, due to a directory-listing vulnerability, a remote attacker can view log files, located in /websocket/logs/, that contain a user's cookie values and the predefined developer's cookie value.
Published 2020-12-10 · Modified
5.3EPSS 0.015