QID 48240
Date Published: 2023-07-28
QID 48240: Remote Management Service Accepting Unencrypted Credentials Detected (PostgreSQL)
A remote management service that accepts unencrypted credentials was detected on the target host.
Services like PostgreSQL with basic auth are checked.
Sending login information without encryption can leave it vulnerable to interception by attackers on the same network using a "network sniffer." This can result in unauthorized access to sensitive data.
Solution
If possible, use alternate services that provide encryption.
Using strong cryptography, render all authentication credentials (such as passwords/phrases) unreadable during transmission.
Using strong cryptography, render all authentication credentials (such as passwords/phrases) unreadable during transmission.
Vendor References
CVEs related to QID 48240
Software Advisories
| Advisory ID | Software | Component | Link |
|---|