#VU26368 Information disclosure in VBASE Editor and VBASE Web-Remote Module - CVE-2020-7000

 

#VU26368 Information disclosure in VBASE Editor and VBASE Web-Remote Module - CVE-2020-7000

Published: March 25, 2020


Vulnerability identifier: #VU26368
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2020-7000
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
VBASE Editor
VBASE Web-Remote Module
Software vendor:
Visam

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to insecure storage of sensitive information. A remote attacker can discover the cryptographic key from the web server and gain information about the login and the encryption/decryption mechanism, which may be exploited to bypass authentication of the HTML5 HMI web interface.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links