8
CVE-2021-32003
- EPSS 0.23%
- Veröffentlicht 05.08.2021 21:15:12
- Zuletzt bearbeitet 21.11.2024 06:06:41
- Quelle VulnerabilityReporting@secomea
- CVE-Watchlists
- Unerledigt
Configuration service port remains open 10 minutes after reboot even when already provisioned
Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Secomea ≫ Sitemanager Firmware Version < 9.5.621256022
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.133 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
| VulnerabilityReporting@secomea.com | 8 | 2.1 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CWE-523 Unprotected Transport of Credentials
Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.
https://www.secomea.com/support/cybersecurity-advisory