Описание
In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, an attacker with network access to the integrated web server could retrieve default or user defined credentials stored and transmitted in an insecure manner.
Ссылки
- MitigationThird Party AdvisoryUS Government Resource
- MitigationThird Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 4107600010.23 (исключая)
Одновременно
cpe:2.3:o:beaconmedaes:scroll_medical_air_systems_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:beaconmedaes:scroll_medical_air_systems:-:*:*:*:*:*:*:*
EPSS
Процентиль: 46%
0.00236
Низкий
9.8 Critical
CVSS3
5 Medium
CVSS2
Дефекты
CWE-522
CWE-522
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, an attacker with network access to the integrated web server could retrieve default or user defined credentials stored and transmitted in an insecure manner.
EPSS
Процентиль: 46%
0.00236
Низкий
9.8 Critical
CVSS3
5 Medium
CVSS2
Дефекты
CWE-522
CWE-522