9.1
CVE-2026-8673
- EPSS 0.19%
- Veröffentlicht 22.05.2026 13:18:16
- Zuletzt bearbeitet 02.06.2026 14:53:30
- Quelle vulnerability@ncsc.ch
- CVE-Watchlists
- Unerledigt
Password re-initialization mechanism sends passwords in plain text
Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks. This issue affects Avantra: before 25.3.0.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.089 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
| vulnerability@ncsc.ch | 5.9 | 0.7 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
|
CWE-523 Unprotected Transport of Credentials
Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.
https://support.avantra.com/hc/en-us/articles/5535621927071