CVE-2023-41965
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Sending some requests in the web application of the vulnerable device allows information to be obtained due to the lack of security in the authentication process.
Affected (1)
Products: Socomec: Modulys Gp Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 01.12.10 |
| Running on/with | Platform Versions |
|---|---|
Socomec Modulys Gp | All versions |
Related CWEs
CWE-921
Storage of Sensitive Data in a Mechanism without Access Control
The product stores sensitive information in a file system or device that does not have built-in access control.
CWE-922
Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
References (2)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.