Innominate mGuard Exposure of Sensitive Information to an Unauthorized Actor
Vulnerability Description
Innominate mGuard before 7.6.4 and 8.x before 8.0.3 does not require authentication for snapshot downloads, which allows remote attackers to obtain sensitive information via a crafted HTTPS request.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-2356
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Applied Risk Research team
More from Innominate
View All →Affected Vendor
Innominate
View all reports →