Fiche vulnérabilité
CVE-2023-39452 : faille élevée socomec modulys gp firmware (CVSS 7.5)
Description
The web application that owns the device clearly stores the credentials within the user management section. Obtaining this information can be done remotely due to the incorrect management of the sessions in the web application.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 18 sept. 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- socomec modulys gp firmware