Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-35vr-x655-89wj

Опубликовано: 03 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the log file, an attacker could retrieve the SQL query sent to the application in plaint text. This log file contains the password hashes coded with AES-CBC-128 bits algorithm, which can be decrypted with a .NET function, obtaining the username's password in plain text.

A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the log file, an attacker could retrieve the SQL query sent to the application in plaint text. This log file contains the password hashes coded with AES-CBC-128 bits algorithm, which can be decrypted with a .NET function, obtaining the username's password in plain text.

EPSS

Процентиль: 13%
0.00044
Низкий

8.2 High

CVSS3

Дефекты

CWE-327
CWE-532

Связанные уязвимости

CVSS3: 8.2
nvd
больше 2 лет назад

A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the log file, an attacker could retrieve the SQL query sent to the application in plaint text. This log file contains the password hashes coded with AES-CBC-128 bits algorithm, which can be decrypted with a .NET function, obtaining the username's password in plain text.

EPSS

Процентиль: 13%
0.00044
Низкий

8.2 High

CVSS3

Дефекты

CWE-327
CWE-532