PT-2022-19806 · Delta Controls · Entelitouch
Gjoko Krstic
·
Published
2022-05-27
·
Updated
2022-06-10
·
CVE-2022-29733
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Delta Controls enteliTOUCH versions 3.33.4005, 3.40.3706, 3.40.3935
Description
The issue allows attackers to intercept HTTP Cookie authentication credentials via a man-in-the-middle attack because sensitive information is transmitted and stored in cleartext.
Recommendations
For versions 3.33.4005, 3.40.3706, and 3.40.3935, consider disabling HTTP authentication until a patch is available to prevent man-in-the-middle attacks.
Restrict access to sensitive information to minimize the risk of exploitation.
Avoid using cleartext storage for sensitive data until the issue is resolved.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Entelitouch