An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interface, information on all users, including passwords, can be found in cleartext in the backup file. An attacker capable of accessing the web interface can create the backup file.
CVE Status: Awaiting Analysis
Attribute | Value |
---|---|
Attack Complexity | LOW |
Attack Vector | ADJACENT_NETWORK |
Availability Impact | NONE |
Base Score | 5.4 |
Base Severity | MEDIUM |
Confidentiality Impact | LOW |
Integrity Impact | LOW |
Privileges Required | NONE |
Scope | UNCHANGED |
User Interaction | NONE |
Vector String | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Exploitability Score | 2.8 |
Impact Score | 2.5 |
Source | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
Type | Secondary |