CVE-2023-0356

SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on HTTP connections, which could result in threat actors obtaining sensitive information.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-23-024-02 Third Party Advisory US Government Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-23-024-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:socomec:net_vision:*:*:*:*:*:*:*:*
cpe:2.3:h:socomec:modulys_gp:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:37

Type Values Removed Values Added
References () https://www.cisa.gov/uscert/ics/advisories/icsa-23-024-02 - Third Party Advisory, US Government Resource () https://www.cisa.gov/uscert/ics/advisories/icsa-23-024-02 - Third Party Advisory, US Government Resource
Summary
  • (es) Las versiones 7.20 y anteriores de SOCOMEC MODULYS GP Netvision carecen de un cifrado sólido para las credenciales en las conexiones HTTP, lo que podría provocar que los actores de amenazas obtengan información confidencial.
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 5.7

07 Nov 2023, 04:00

Type Values Removed Values Added
Summary SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on HTTP connections, which could result in threat actors obtaining sensitive information. SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on HTTP connections, which could result in threat actors obtaining sensitive information.

Information

Published : 2023-01-26 21:18

Updated : 2024-11-21 07:37


NVD link : CVE-2023-0356

Mitre link : CVE-2023-0356

CVE.ORG link : CVE-2023-0356


JSON object : View

Products Affected

socomec

  • modulys_gp
  • net_vision
CWE
CWE-261

Weak Encoding for Password