Описание
GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the passwords and gain privileges.
Ссылки
- Broken Link
- Broken LinkThird Party AdvisoryVDB Entry
- Broken Link
- Third Party AdvisoryUS Government Resource
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkThird Party AdvisoryVDB Entry
- Broken Link
- Broken LinkThird Party AdvisoryVDB Entry
- Broken Link
- Third Party AdvisoryUS Government Resource
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 2.6 (включая)
cpe:2.3:a:ge:proficy_real-time_information_portal:*:*:*:*:*:*:*:*
EPSS
Процентиль: 87%
0.03223
Низкий
9.8 Critical
CVSS3
5 Medium
CVSS2
Дефекты
CWE-312
Связанные уязвимости
CVSS3: 9.8
github
почти 4 года назад
GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the passwords and gain privileges.
EPSS
Процентиль: 87%
0.03223
Низкий
9.8 Critical
CVSS3
5 Medium
CVSS2
Дефекты
CWE-312