Socomec MOD3GP-SY-120K Plaintext Storage of a Password
CVE-2023-39452

7.5HIGH

Key Information:

Vendor

Socomec

Vendor
CVE Published:
18 September 2023

What is CVE-2023-39452?

A vulnerability in the web application allows for the remote exposure of user credentials due to improper session management. This flaw lies within the user management section, where sensitive credentials are stored inadequately. Attackers can exploit this vulnerability to access sensitive information without proper authorization.

Affected Version(s)

MODULYS GP (MOD3GP-SY-120K) v01.12.10

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aarón Flecha Menéndez reported these vulnerabilities to CISA.
.