← back
CVE-2019-13947

CVE-2019-13947

CVSS 4.9 MEDIUMEPSS 0.9%CWE-317
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.9EPSS 0.9%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
12 Dec 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The user configuration menu in the web interface of the Control Center Server (CCS) transfers user passwords in clear to the client (browser). An attacker with administrative privileges for the web interface could be able to read (and not only reset) passwords of other CCS users.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N/E:F/RL:U/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →