TROYANOSYVIRUS
Voltar para CVEs

CVE-2023-33730

CRITICAL
9.8

Descricao

Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacker to retrieve password of any admin or normal user in plain text format.

Detalhes CVE

Pontuacao CVSS v3.19.8
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado5/31/2023
Ultima modificacao1/10/2025
Fontenvd
Avistamentos honeypot0

Produtos afetados

escanav:escan_management_console

Fraquezas (CWE)

CWE-319CWE-319

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.