CVE-2023-27927
Summary
| CVE | CVE-2023-27927 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-27 20:15:00 UTC |
| Updated | 2023-11-07 04:10:00 UTC |
| Description | An authenticated malicious user could acquire the simple mail transfer protocol (SMTP) Password in cleartext format, despite it being protected and hidden behind asterisks. The attacker could then perform further attacks using the SMTP credentials. |
Risk And Classification
Problem Types: CWE-319
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Sauter-controls | Ey-as525f001 | - | All | All | All |
| Operating System | Sauter-controls | Ey-as525f001 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SAUTER EY-modulo 5 Building Automation Stations | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.