8.8

CVE-2023-37362

Weintek Weincloud Improper Authentication

Weintek Weincloud v0.13.6

 

could allow an attacker to abuse the registration functionality to login with testing credentials to the official website.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WeintekWeincloud Version0.13.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.394
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ics-cert@hq.dhs.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

https://www.cisa.gov/news-events/ics-advisories/icsa-23-199-04
Third Party Advisory
US Government Resource