The Clorius Controls Java web client before 01.00.0009g allows remote attackers to discover credentials by sniffing the network for cleartext-equivalent traffic.
References
Link | Resource |
---|---|
http://www.cloriuscontrols.com | |
https://www.cisa.gov/news-events/ics-advisories/icsa-15-013-02 | |
https://ics-cert.us-cert.gov/advisories/ICSA-15-013-02 | Third Party Advisory US Government Resource |
Configurations
History
05 Sep 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-326 | |
References |
|
|
CVSS |
v2 : v3 : |
v2 : 10.0
v3 : unknown |
Information
Published : 2015-01-17 02:59
Updated : 2025-09-05 22:15
NVD link : CVE-2014-9199
Mitre link : CVE-2014-9199
CVE.ORG link : CVE-2014-9199
JSON object : View
Products Affected
clorius_controls_a\/s
- java_web_client