Описание
An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due to an invalid SSL certificate. The attack allows for an eavesdropper to capture the communication and decrypt the data.
Ссылки
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryUS Government Resource
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 6.4.414.084 (исключая)
cpe:2.3:a:orpak:siteomat:*:*:*:*:*:*:*:*
EPSS
Процентиль: 72%
0.00713
Низкий
9.8 Critical
CVSS3
5 Medium
CVSS2
Дефекты
CWE-310
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due to an invalid SSL certificate. The attack allows for an eavesdropper to capture the communication and decrypt the data.
EPSS
Процентиль: 72%
0.00713
Низкий
9.8 Critical
CVSS3
5 Medium
CVSS2
Дефекты
CWE-310