7.5
CVE-2023-31277
- EPSS 0.46%
- Veröffentlicht 06.07.2023 23:15:09
- Zuletzt bearbeitet 21.11.2024 08:01:43
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
PiiGAB M-Bus Unprotected Transport of Credentials
PiiGAB M-Bus transmits credentials in plaintext format.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Piigab ≫ M-bus 900s Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.46% | 0.362 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| ics-cert@hq.dhs.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-523 Unprotected Transport of Credentials
Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.
https://www.cisa.gov/news-events/ics-advisories/icsa-23-187-01