Cleartext transmission of sensitive information in Ampla MES - CVE-2017-9637

 

Cleartext transmission of sensitive information in Ampla MES - CVE-2017-9637

Published: July 7, 2017


Vulnerability identifier: #VU7374
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9637
CWE-ID: CWE-319
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to obtain credentials on the target system.

The weakness exists due to cleartext transmission of sensitive information. When connectivity to third party databases is configured to use a SQL user name and password, a local attacker sniff details from the connection string.

Successful exploitation may result in compromise of credentials used to connect to third party databases.


Affected software

Ampla MES

How to mitigate CVE-2017-9637

Update to version 6.5.


External References

Related Security Bulletins