PT-2018-18123 · Beaconmedaes · Totalalert Web Application
Maxim Rupp
·
Publicado
2018-05-24
·
Atualizado
2019-10-09
·
CVE-2018-7518
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems versions prior to 4107600010.23
Description
The issue allows an attacker with network access to the integrated web server to retrieve default or user-defined credentials. These credentials are stored and transmitted in an insecure manner.
Recommendations
For versions prior to 4107600010.23, update to version 4107600010.23 or later to resolve the issue.
Correção
Insufficiently Protected Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Totalalert Web Application