PT-2024-15655 · Wic200 · Wic200
Hadess
·
Published
2024-01-16
·
Updated
2024-01-23
·
CVE-2024-0556
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WIC200 version 1.1
Description
A Weak Cryptography for Passwords issue has been detected, allowing a remote user to intercept traffic and retrieve credentials from another user. The credentials can be decoded from base64, enabling the attacker to view them in plain text.
Recommendations
For version 1.1, consider updating the cryptography mechanism to a more secure standard to prevent interception and decoding of credentials. As a temporary workaround, restrict access to sensitive areas of the system to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wic200