CVE-2023-0356

SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on HTTP connections, which could result in threat actors obtaining sensitive information.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-23-024-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:socomec:net_vision:*:*:*:*:*:*:*:*
cpe:2.3:h:socomec:modulys_gp:-:*:*:*:*:*:*:*

History

07 Nov 2023, 04:00

Type Values Removed Values Added
Summary SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on HTTP connections, which could result in threat actors obtaining sensitive information. SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on HTTP connections, which could result in threat actors obtaining sensitive information.

06 Feb 2023, 18:38

Type Values Removed Values Added
References (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-23-024-02 - (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-23-024-02 - Third Party Advisory, US Government Resource
CPE cpe:2.3:h:socomec:modulys_gp:-:*:*:*:*:*:*:*
cpe:2.3:a:socomec:net_vision:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Socomec
Socomec net Vision
Socomec modulys Gp

26 Jan 2023, 21:18

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-26 21:18

Updated : 2023-12-10 14:48


NVD link : CVE-2023-0356

Mitre link : CVE-2023-0356

CVE.ORG link : CVE-2023-0356


JSON object : View

Products Affected

socomec

  • modulys_gp
  • net_vision
CWE
CWE-261

Weak Encoding for Password