Overview :
This advisory addresses a Information Disclosure vulnerability in Verodin Director affecting version 3.5.3.1 and earlier where an attacker can reveal usernames and passwords of integrated security technologies via a /integrations.json JSON REST API request.
Affected Product(s) :
  • Verodin Director version 3.5.3.1 and earlier
Vulnerability Details :
CVE ID :CVE-2019-10716
An attacker must have an existing authenticated connection to the Director (web interface) of Verodin and make a HTTP GET request to the /integrations.json JSON REST API endpoint.

Disclosure of usernames and passwords that integrations use to contact the security technologies.

Solution :
This vulnerability is mitigated by the requirement that the attacker must be authenticated with the Verodin Director (web interface).