Описание
The default configuration of Tridium Niagara AX Framework through 3.6 uses a cleartext base64 format for transmission of credentials in cookies, which allows remote attackers to obtain sensitive information by sniffing the network.
Ссылки
- Broken LinkPatchVendor Advisory
- Broken LinkThird Party AdvisoryUS Government Resource
- Broken LinkPatchVendor Advisory
- Broken LinkThird Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 3.6 (включая)
cpe:2.3:a:tridium:niagara_ax:*:*:*:*:*:*:*:*
EPSS
Процентиль: 73%
0.00787
Низкий
5 Medium
CVSS2
Дефекты
CWE-522
Связанные уязвимости
github
больше 3 лет назад
The default configuration of Tridium Niagara AX Framework through 3.6 uses a cleartext base64 format for transmission of credentials in cookies, which allows remote attackers to obtain sensitive information by sniffing the network.
EPSS
Процентиль: 73%
0.00787
Низкий
5 Medium
CVSS2
Дефекты
CWE-522