7.5
CVE-2023-7237
- EPSS 0.31%
- Veröffentlicht 23.01.2024 22:15:16
- Zuletzt bearbeitet 21.11.2024 08:45:34
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
Lantronix XPort Weak Encoding for Password
Lantronix XPort sends weakly encoded credentials within web request headers.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lantronix ≫ Xport Edge Firmware Version2.0.0.13
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.219 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| ics-cert@hq.dhs.gov | 5.7 | 2.1 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
CWE-261 Weak Encoding for Password
Obscuring a password with a trivial encoding does not protect the password.
CWE-326 Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
https://www.cisa.gov/news-events/ics-advisories/icsa-24-023-05
https://www.lantronix.com/products/xport-edge/