Innominate mGuard before 7.6.4 and 8.x before 8.0.3 does not require authentication for snapshot downloads, which allows remote attackers to obtain sensitive information via a crafted HTTPS request.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-14-189-02 | |
| http://ics-cert.us-cert.gov/advisories/ICSA-14-189-02 | Third Party Advisory US Government Resource | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    03 Oct 2025, 18:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : 4.3 v3 : unknown | 
| References | 
 | 
21 Nov 2024, 02:06
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://ics-cert.us-cert.gov/advisories/ICSA-14-189-02 - Third Party Advisory, US Government Resource | 
Information
                Published : 2014-07-30 14:55
Updated : 2025-10-03 18:15
NVD link : CVE-2014-2356
Mitre link : CVE-2014-2356
CVE.ORG link : CVE-2014-2356
JSON object : View
Products Affected
                innominate
- mguard_firmware
CWE
                
                    
                        
                        CWE-200
                        
            Exposure of Sensitive Information to an Unauthorized Actor
