Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-49wh-vw4x-p83m

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthorized actors. Basic authentication is used for the authentication, making it possible to base64 decode the sniffed credentials and discover the username and password.

The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthorized actors. Basic authentication is used for the authentication, making it possible to base64 decode the sniffed credentials and discover the username and password.

EPSS

Процентиль: 42%
0.00198
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-319
CWE-522

Связанные уязвимости

CVSS3: 9.8
nvd
больше 6 лет назад

The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthorized actors. Basic authentication is used for the authentication, making it possible to base64 decode the sniffed credentials and discover the username and password.

EPSS

Процентиль: 42%
0.00198
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-319
CWE-522