| |
Vulnerability CVE-2022-27179
Published: 2022-04-20
Description: |
A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain access to the protected resource. If the same passwords were used for other resources, further such assets may be compromised. |
Type:
CWE-522 (Insufficiently Protected Credentials)
CVSS2 => (AV:N/AC:L/Au:S/C:P/I:N/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
4/10 |
2.9/10 |
8/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
None |
None |
References: |
https://www.cisa.gov/uscert/ics/advisories/icsa-22-104-03
|
|
|
Copyright 2024, cxsecurity.com
|
|
|