PT-2023-5301 · Unknown · Modulys Gp
Aarón Flecha Menéndez
·
Published
2023-09-07
·
Updated
2024-08-02
·
CVE-2023-39452
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MODULYS GP (MOD3GP-SY-120K) (affected versions not specified)
Description
The web application that owns the device clearly stores the credentials within the user management section. Obtaining this information can be done remotely due to the incorrect management of the sessions in the web application. This issue is related to the storage of passwords in plaintext. An attacker can exploit this to gain unauthorized access to protected information.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Modulys Gp