7.5

CVE-2023-39452

Socomec MOD3GP-SY-120K Plaintext Storage of a Password















The web application that owns the device clearly stores the credentials within the user management section. Obtaining this information can be done remotely due to the incorrect management of the sessions in the web application.















Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SocomecModulys Gp Firmware Version01.12.10
   SocomecModulys Gp Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.5% 0.386
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
ics-cert@hq.dhs.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-256 Plaintext Storage of a Password

Storing a password in plaintext may result in a system compromise.

https://www.cisa.gov/news-events/ics-advisories/icsa-23-250-03
Third Party Advisory
US Government Resource