Описание
The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong enough for the level of protection required. A local attacker could alter the existing configuration and ultimately gain privileged access to the PcVue application.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 17.0.0 (исключая)
cpe:2.3:a:arcinfo:pcvue:*:*:*:*:*:*:*:*
EPSS
Процентиль: 0%
0.00064
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-326
Связанные уязвимости
CVSS3: 5.5
github
около 2 месяцев назад
The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong enough for the level of protection required. A local attacker could alter the existing configuration and ultimately gain privileged access to the PcVue application.
EPSS
Процентиль: 0%
0.00064
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-326