PT-2022-14909 · Bachmann Visutec Gmbh · Atvise
Martin Zeiser
·
Published
2022-06-17
·
Updated
2022-06-30
·
CVE-2022-21184
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Bachmann Visutec GmbH Atvise versions 3.5.4 through 3.7
Description
An information disclosure issue exists in the License registration functionality. A plaintext HTTP request can lead to a disclosure of login credentials. An attacker can perform a man-in-the-middle attack to trigger this issue.
Recommendations
For versions 3.5.4 through 3.7, consider disabling the License registration functionality until a patch is available to prevent exploitation. Restrict access to sensitive areas of the application to minimize the risk of login credential disclosure.
Fix
Insufficiently Protected Credentials
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Atvise