CVE-2023-39452
Published on: Not Yet Published
Last Modified on: 09/21/2023 06:30:00 PM UTC
Certain versions of Modulys Gp from Socomec contain the following vulnerability:
** UNSUPPPORTED WHEN ASSIGNED ** The web application that owns the device clearly stores the credentials within the user management section. Obtaining this information can be done remotely due to the incorrect management of the sessions in the web application.
- CVE-2023-39452 has been assigned by
ics-[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Socomec - MODULYS GP (MOD3GP-SY-120K) version = v01.12.10
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Socomec MOD3GP-SY-120K | CISA | www.cisa.gov text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Socomec | Modulys Gp | - | All | All | All |
Operating System | Socomec | Modulys Gp Firmware | 01.12.10 | All | All | All |
- cpe:2.3:h:socomec:modulys_gp:-:*:*:*:*:*:*:*:
- cpe:2.3:o:socomec:modulys_gp_firmware:01.12.10:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE