Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fjxv-6346-8j89

Опубликовано: 12 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users unauthorized access to the underlying data sources.

An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users unauthorized access to the underlying data sources.

EPSS

Процентиль: 50%
0.00272
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 4.7
nvd
около 3 лет назад

An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users unauthorized access to the underlying data sources.

CVSS3: 6.5
fstec
около 3 лет назад

Уязвимость SCADA-системы PcVue, связанная с раскрытием информации через регистрационные файлы, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 50%
0.00272
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-532