7.5
CVE-2023-39452
- EPSS 0.09%
- Veröffentlicht 18.09.2023 21:16:04
- Zuletzt bearbeitet 21.11.2024 08:15:27
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
The web application that owns the device clearly stores the credentials within the user management section. Obtaining this information can be done remotely due to the incorrect management of the sessions in the web application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Socomec ≫ Modulys Gp Firmware Version01.12.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.251 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| ics-cert@hq.dhs.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-256 Plaintext Storage of a Password
Storing a password in plaintext may result in a system compromise.