9.8
CVE-2018-7820
- EPSS 0.28%
- Published 17.09.2019 20:15:11
- Last modified 21.11.2024 04:12:47
- Source cybersecurity@se.com
- Teams watchlist Login
- Open Login
A Credentials Management CWE-255 vulnerability exists in the APC UPS Network Management Card 2 AOS v6.5.6, which could cause Remote Monitoring Credentials to be viewed in plaintext when Remote Monitoring is enabled, and then disabled.
Data is provided by the National Vulnerability Database (NVD)
Schneider-electric ≫ Ap9630 Firmware Version < 6.7.2
Schneider-electric ≫ Smart-ups Srt 5kva Firmware Version < 6.7.2
Schneider-electric ≫ Ap9631 Firmware Version < 6.7.2
Schneider-electric ≫ Ap9635 Firmware Version < 6.7.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.28% | 0.486 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.