7.5
CVE-2023-39227
- EPSS 0.27%
- Veröffentlicht 11.09.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:14:57
- CVE-Watchlists
- Unerledigt
Softneta MedDream PACS Plaintext Storage of a Password
Softneta MedDream PACS stores usernames and passwords in plaintext. The plaintext storage could be abused by attackers to leak legitimate user’s credentials.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Softneta ≫ Meddream Pacs SwEditionpremium Version <= 7.2.8.810
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.184 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| DHS.gov | 6.1 | 1.8 | 4.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
|
CWE-256 Plaintext Storage of a Password
The product stores a password in plaintext within resources such as memory or files.
https://www.cisa.gov/news-events/ics-medical-advisories/icsma-23-248-01