VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow an unauthenticated attacker to discover the cryptographic key from the web server and gain information about the login and the encryption/decryption mechanism, which may be exploited to bypass authentication of the HTML5 HMI web interface.
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Vbase_editor | Visam | 11.5.0.2 (including) | 11.5.0.2 (including) |
| Vbase_web-remote | Visam | - (including) | - (including) |