9.8
CVE-2018-7518
- EPSS 0.24%
- Veröffentlicht 24.05.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:17
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, an attacker with network access to the integrated web server could retrieve default or user defined credentials stored and transmitted in an insecure manner.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Beaconmedaes ≫ Scroll Medical Air Systems Firmware Version < 4107600010.23
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.463 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.