CVE-2023-41965
18.09.2023, 20:15
Sending some requests in the web application of the vulnerable device allows information to be obtained due to the lack of security in the authentication process.Enginsight
Vendor | Product | Version |
---|---|---|
socomec | modulys_gp_firmware | 01.12.10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-921 - Storage of Sensitive Data in a Mechanism without Access ControlThe software stores sensitive information in a file system or device that does not have built-in access control.
- CWE-922 - Insecure Storage of Sensitive InformationThe software stores sensitive information without properly limiting read or write access by unauthorized actors.