PT-2023-5301 · Unknown · Modulys Gp

Aarón Flecha Menéndez

·

Published

2023-09-07

·

Updated

2024-08-02

·

CVE-2023-39452

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions MODULYS GP (MOD3GP-SY-120K) (affected versions not specified)
Description The web application that owns the device clearly stores the credentials within the user management section. Obtaining this information can be done remotely due to the incorrect management of the sessions in the web application. This issue is related to the storage of passwords in plaintext. An attacker can exploit this to gain unauthorized access to protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2023-05927
CVE-2023-39452

Affected Products

Modulys Gp