Vulnerabilities (CVE)

Filtered by CWE-523
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-31277 1 Piigab 2 M-bus 900s, M-bus 900s Firmware 2023-12-10 N/A 7.5 HIGH
PiiGAB M-Bus transmits credentials in plaintext format.
CVE-2023-28708 1 Apache 1 Tomcat 2023-12-10 N/A 4.3 MEDIUM
When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel.
CVE-2022-31805 1 Codesys 10 Development System, Edge Gateway, Gateway and 7 more 2023-12-10 4.3 MEDIUM 7.5 HIGH
In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.