PT-2017-13198 · Prominent · Prominent Multiflex M10A Controller

Published

2017-10-17

·

Updated

2019-10-09

·

CVE-2017-14009

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ProMinent MultiFLEX M10a Controller (affected versions not specified)
Description An Information Exposure issue was discovered in the web interface of the ProMinent MultiFLEX M10a Controller. When an authenticated user uses the Change Password feature, the current password for the user is specified in plaintext. This may allow an attacker who has been authenticated to gain access to the password.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Transmission of Sensitive Information

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-14009

Affected Products

Prominent Multiflex M10A Controller