CVE-2023-3350
Last modified
CVE-2023-3350 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the log file, an attacker could retrieve the SQL query sent to the application in plaint text. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the log file, an attacker could retrieve the SQL query sent to the application in plaint text. This log file contains the password hashes coded with AES-CBC-128 bits algorithm, which can be decrypted with a .NET function, obtaining the username's password in plain text.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ayesa | Ibermatica Rps | 2019 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-3350?
How severe is CVE-2023-3350?
How do I fix CVE-2023-3350?
Are you affected by CVE-2023-3350?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
