HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of the webservices used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It unnecessarily exposes sensitive information about the server configuration.
References
History

Thu, 26 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Feb 2026 08:15:00 +0000

Type Values Removed Values Added
Description HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of the webservices used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It unnecessarily exposes sensitive information about the server configuration.
Title Server configuration details in HTTP headers
First Time appeared Arcinfo
Arcinfo pcvue
Weaknesses CWE-201
CPEs cpe:2.3:a:arcinfo:pcvue:*:*:*:*:*:*:*:*
cpe:2.3:a:arcinfo:pcvue:12.0.0:*:*:*:*:*:*:*
Vendors & Products Arcinfo
Arcinfo pcvue
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/AU:Y/R:U/RE:M/U:Clear'}


cve-icon MITRE

Status: PUBLISHED

Assigner: arcinfo

Published: 2026-02-26T07:56:57.048Z

Updated: 2026-02-26T14:22:11.880Z

Reserved: 2026-01-30T08:37:56.659Z

Link: CVE-2026-1694

cve-icon Vulnrichment

Updated: 2026-02-26T14:22:07.242Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-26T08:16:18.763

Modified: 2026-02-27T14:06:59.787

Link: CVE-2026-1694

cve-icon Redhat

No data.