#VU8824 Information disclosure in MultiFLEX M10a Controller - CVE-2017-14009

 

#VU8824 Information disclosure in MultiFLEX M10a Controller - CVE-2017-14009

Published: October 13, 2017


Vulnerability identifier: #VU8824
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-14009
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
MultiFLEX M10a Controller
Software vendor:
ProMinent

Description

The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information on the target system.

The weakness exists due to the current password for the user is specified in plaintext. A remote attacker can use the “Change Password” feature on the application and gain access to the password.

Remediation

Cybersecurity Help is currently unaware of any solutions addressing the vulnerability.

External links