Socomec MOD3GP-SY-120K Plaintext Storage of a Password
CVE-2023-39452
7.5HIGH
What is CVE-2023-39452?
A vulnerability in the web application allows for the remote exposure of user credentials due to improper session management. This flaw lies within the user management section, where sensitive credentials are stored inadequately. Attackers can exploit this vulnerability to access sensitive information without proper authorization.
Affected Version(s)
MODULYS GP (MOD3GP-SY-120K) v01.12.10
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Aarón Flecha Menéndez reported these vulnerabilities to CISA.