Socomec DIRIS A-40 devices before 48250501 are susceptible to a password disclosure vulnerability in the web interface that could allow remote attackers to get full access to a device via the /password.jsn URI.
id: CVE-2019-15859
info:
name: Socomec DIRIS A-40 Devices Password Disclosure
author: geeknik
...