The web application that owns the device clearly stores the credentials within the user management section. Obtaining this information can be done remotely due to the incorrect management of the sessions in the web application.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-23-250-03 | Third Party Advisory US Government Resource | 
| https://www.cisa.gov/news-events/ics-advisories/icsa-23-250-03 | Third Party Advisory US Government Resource | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    No history.
Information
                Published : 2023-09-18 21:16
Updated : 2024-11-21 08:15
NVD link : CVE-2023-39452
Mitre link : CVE-2023-39452
CVE.ORG link : CVE-2023-39452
JSON object : View
Products Affected
                socomec
- modulys_gp_firmware
- modulys_gp
CWE
                
                    
                        
                        CWE-256
                        
            Plaintext Storage of a Password
