7.5
CVE-2023-39227
- EPSS 0.08%
- Veröffentlicht 11.09.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:14:57
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
Softneta MedDream PACS stores usernames and passwords in plaintext. The plaintext storage could be abused by attackers to leak legitimate user’s credentials.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Softneta ≫ Meddream Pacs SwEditionpremium Version <= 7.2.8.810
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.247 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| ics-cert@hq.dhs.gov | 6.1 | 1.8 | 4.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
|
CWE-256 Plaintext Storage of a Password
Storing a password in plaintext may result in a system compromise.