CVE-2022-38469

An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.
References
Link Resource
https://digitalsupport.ge.com/s/article/GE-Digital-Product-Security-Advisory-GED-23-01 Permissions Required Vendor Advisory
https://www.cisa.gov/uscert/ics/advisories/icsa-23-017-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:a:ge:proficy_historian:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:50

Type Values Removed Values Added
Summary An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords. An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.

21 Jul 2023, 20:32

Type Values Removed Values Added
CWE CWE-326 CWE-522

25 Jan 2023, 17:19

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-261 CWE-326
References (MISC) https://digitalsupport.ge.com/s/article/GE-Digital-Product-Security-Advisory-GED-23-01 - (MISC) https://digitalsupport.ge.com/s/article/GE-Digital-Product-Security-Advisory-GED-23-01 - Permissions Required, Vendor Advisory
References (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-23-017-01 - (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-23-017-01 - Third Party Advisory, US Government Resource
First Time Ge
Ge proficy Historian
CPE cpe:2.3:a:ge:proficy_historian:*:*:*:*:*:*:*:*

18 Jan 2023, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-18 00:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-38469

Mitre link : CVE-2022-38469

CVE.ORG link : CVE-2022-38469


JSON object : View

Products Affected

ge

  • proficy_historian
CWE
CWE-522

Insufficiently Protected Credentials

CWE-261

Weak Encoding for Password