PT-2018-18123 · Beaconmedaes · Totalalert Web Application

Maxim Rupp

·

Published

2018-05-24

·

Updated

2019-10-09

·

CVE-2018-7518

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems versions prior to 4107600010.23
Description The issue allows an attacker with network access to the integrated web server to retrieve default or user-defined credentials. These credentials are stored and transmitted in an insecure manner.
Recommendations For versions prior to 4107600010.23, update to version 4107600010.23 or later to resolve the issue.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-7518

Affected Products

Totalalert Web Application