Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vcx5-gghv-x2hh

Опубликовано: 14 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

The access control in CemiPark software stores integration (e.g. FTP or SIP) credentials in plain-text. An attacker who gained unauthorized access to the device can retrieve clear text passwords used by the system.This issue affects CemiPark software: 4.5, 4.7, 5.03 and potentially others. The vendor refused to provide the specific range of affected products.

The access control in CemiPark software stores integration (e.g. FTP or SIP) credentials in plain-text. An attacker who gained unauthorized access to the device can retrieve clear text passwords used by the system.This issue affects CemiPark software: 4.5, 4.7, 5.03 and potentially others. The vendor refused to provide the specific range of affected products.

EPSS

Процентиль: 35%
0.00147
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-256

Связанные уязвимости

CVSS3: 5.4
nvd
больше 1 года назад

The access control in CemiPark software stores integration (e.g. FTP or SIP) credentials in plain-text. An attacker who gained unauthorized access to the device can retrieve clear text passwords used by the system.This issue affects CemiPark software: 4.5, 4.7, 5.03 and potentially others. The vendor refused to provide the specific range of affected products.

EPSS

Процентиль: 35%
0.00147
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-256