Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-4311

Опубликовано: 12 дек. 2022
Источник: nvd
CVSS3: 4.7
CVSS3: 6.5
EPSS Низкий

Описание

An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users unauthorized access to the underlying data sources.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:arcinformatique:pcvue:*:*:*:*:*:*:*:*
Версия от 15 (включая) до 15.2.2 (включая)

EPSS

Процентиль: 50%
0.00272
Низкий

4.7 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 6.5
github
около 3 лет назад

An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users unauthorized access to the underlying data sources.

CVSS3: 6.5
fstec
около 3 лет назад

Уязвимость SCADA-системы PcVue, связанная с раскрытием информации через регистрационные файлы, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 50%
0.00272
Низкий

4.7 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-532