← volver
CVE-2019-13947

CVE-2019-13947

CVSS 4.9 MEDIUMEPSS 0.9%CWE-317
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 4.9EPSS 0.9%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
12 dic 2019Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The user configuration menu in the web interface of the Control Center Server (CCS) transfers user passwords in clear to the client (browser). An attacker with administrative privileges for the web interface could be able to read (and not only reset) passwords of other CCS users.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N/E:F/RL:U/RC:C

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →