PT-2022-14909 · Bachmann Visutec Gmbh · Atvise

Martin Zeiser

·

Published

2022-06-17

·

Updated

2022-06-30

·

CVE-2022-21184

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Bachmann Visutec GmbH Atvise versions 3.5.4 through 3.7
Description An information disclosure issue exists in the License registration functionality. A plaintext HTTP request can lead to a disclosure of login credentials. An attacker can perform a man-in-the-middle attack to trigger this issue.
Recommendations For versions 3.5.4 through 3.7, consider disabling the License registration functionality until a patch is available to prevent exploitation. Restrict access to sensitive areas of the application to minimize the risk of login credential disclosure.

Fix

Insufficiently Protected Credentials

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-21184

Affected Products

Atvise