Skip to content

CVE-2023-39452 | MODULYS GP (MOD3GP-SY-120K)

The web application that owns the device clearly stores the credentials within the user management section. Obtaining this information can be done remotely due to the incorrect management of the sessions in the web application. .This CVE has a CVSS3.1 score of 7.5 and a Base Severity of HIGH.

InfoDetails
CVE IDCVE-2023-39452
CVE StatePUBLISHED
BaseScore7.5
BaseSeverityHIGH
VectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
VersionNA

References for CVE-2023-39452 :
https://www.cisa.gov/news-events/ics-advisories/icsa-23-250-03

Metric TypeMetric Score
AttackVector(AV)NETWORK
AttackComplexity(AC)LOW
PrivilegesRequired(PR)NONE
UserInteraction(UI)NONE
Scope(S)UNCHANGED
Confidentiality(C)HIGH
Availability(A)NONE
Integrity(I)NONE