#VU23706 Cleartext transmission of sensitive information in SPPA-T3000 Application Server - CVE-2019-18285
Published: December 19, 2019
SPPA-T3000 Application Server
Siemens
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to software uses insecure communication channel to transmit sensitive information between the client and the Application Server. A remote attacker with access to the communication channel can read credentials of a valid user.
Note: An attacker needs to have access to the Application Highway in order to exploit this vulnerability.