CVE Vulnerabilities

CVE-2023-29168

Insufficiently Protected Credentials

Published: Jun 07, 2023 | Modified: Jun 16, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Vuforia_studio Ptc * 9.9 (excluding)

Potential Mitigations

References