CVE Vulnerabilities

CVE-2023-0356

Weak Encoding for Password

Published: Jan 26, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on HTTP connections, which could result in threat actors obtaining sensitive information.

Weakness

Obscuring a password with a trivial encoding does not protect the password.

Affected Software

NameVendorStart VersionEnd Version
Net_visionSocomec*7.20 (including)

Potential Mitigations

References