Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6g7p-j2q6-fp39

Опубликовано: 01 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled.

Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled.

EPSS

Процентиль: 37%
0.00162
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 5.9
nvd
около 3 лет назад

Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled. OTE: the vendor's position is that, by design, this is controlled by a configuration option in which a customer can choose to use HTTP (rather than HTTPS) during troubleshooting.

EPSS

Процентиль: 37%
0.00162
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-319