CVE-2022-38469

An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.
References
Link Resource
https://digitalsupport.ge.com/s/article/GE-Digital-Product-Security-Advisory-GED-23-01 Permissions Required Vendor Advisory
https://www.cisa.gov/uscert/ics/advisories/icsa-23-017-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:a:ge:proficy_historian:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:50

Type Values Removed Values Added
Summary An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords. An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.

21 Jul 2023, 20:32

Type Values Removed Values Added
CWE CWE-326 CWE-522

Information

Published : 2023-01-18 00:15

Updated : 2024-02-28 19:51


NVD link : CVE-2022-38469

Mitre link : CVE-2022-38469

CVE.ORG link : CVE-2022-38469


JSON object : View

Products Affected

ge

  • proficy_historian
CWE
CWE-522

Insufficiently Protected Credentials

CWE-261

Weak Encoding for Password