Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-14009

Опубликовано: 17 окт. 2017
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

An Information Exposure issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When an authenticated user uses the Change Password feature on the application, the current password for the user is specified in plaintext. This may allow an attacker who has been authenticated to gain access to the password.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:prominent:multiflex_m10a_controller_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:prominent:multiflex_m10a_controller:-:*:*:*:*:*:*:*

EPSS

Процентиль: 49%
0.00256
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200
CWE-319

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

An Information Exposure issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When an authenticated user uses the Change Password feature on the application, the current password for the user is specified in plaintext. This may allow an attacker who has been authenticated to gain access to the password.

EPSS

Процентиль: 49%
0.00256
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200
CWE-319