CVE Published: 24/01/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: icscert |
Vendor: SOCOMEC |
Product: MODULYS GP Status : PUBLISHED
CVE-2023-0356 Description
SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on HTTP connections, which could result in threat actors obtaining sensitive information.
Metrics
CVSS Version: 3.1 |
Base Score: 5.7 MEDIUM Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N