CVE-2023-27927
Last modified
CVE-2023-27927 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An authenticated malicious user could acquire the simple mail transfer protocol (SMTP) Password in cleartext format, despite it being protected and hidden behind asterisks. The attacker could then perform further attacks using the SMTP credentials.. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
An authenticated malicious user could acquire the simple mail transfer protocol (SMTP) Password in cleartext format, despite it being protected and hidden behind asterisks. The attacker could then perform further attacks using the SMTP credentials.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sauter-Controls | Ey-As525f001 Firmware | All versions |
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-03Third Party Advisory, US Government Resource
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-03Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-27927?
How severe is CVE-2023-27927?
How do I fix CVE-2023-27927?
Are you affected by CVE-2023-27927?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
