← Volver a CVEs
CVE-2022-4311
MEDIUM4.7
Descripcion
An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users unauthorized access to the underlying data sources.
Detalles CVE
Puntuacion CVSS v3.14.7
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Vector de ataqueLOCAL
ComplejidadHIGH
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado12/12/2022
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
arcinformatique:pcvue
Debilidades (CWE)
CWE-532
Referencias
https://www.pcvuesolutions.com/support/index.php/en/security-bulletin/1165-security-bulletin-2022-6(ics-cert@hq.dhs.gov)
https://www.pcvuesolutions.com/support/index.php/en/security-bulletin/1165-security-bulletin-2022-6(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.