SB2019080202 - Insecure communication in 3S-Smart Software Solutions GmbH CODESYS V3 solutions
Published: August 2, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cleartext transmission of sensitive information (CVE-ID: CVE-2019-9013)
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to software allows transmission of user credentials via insecure HTTP protocol. A remote attacker with ability to intercept network traffic can obtain user's credentials and gain unauthorized access to the system.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.