Описание
Communication traffic involving "Ethernet Q Commands" service of Haas Controller version 100.20.000.1110 is transmitted in cleartext. This allows an attacker to obtain sensitive information being passed to and from the controller.
Ссылки
- MitigationThird Party AdvisoryUS Government Resource
- MitigationThird Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:haascnc:haas_controller:100.20.000.1110:*:*:*:*:*:*:*
EPSS
Процентиль: 31%
0.00116
Низкий
9.1 Critical
CVSS3
7.5 High
CVSS3
Дефекты
CWE-319
CWE-319
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
Communication traffic involving "Ethernet Q Commands" service of Haas Controller version 100.20.000.1110 is transmitted in cleartext. This allows an attacker to obtain sensitive information being passed to and from the controller.
EPSS
Процентиль: 31%
0.00116
Низкий
9.1 Critical
CVSS3
7.5 High
CVSS3
Дефекты
CWE-319
CWE-319