Refine your search

1 vulnerability found for KVMS Pro by CP Plus

CVE-2023-1518 (GCVE-0-2023-1518)
Vulnerability from cvelistv5
Published
2023-03-28 20:51
Modified
2025-01-16 21:37
CWE
  • CWE-522 - Insufficiently Protected Credentials
Summary
CP Plus KVMS Pro versions 2.01.0.T.190521 and prior are vulnerable to sensitive credentials being leaked because they are insufficiently protected.  
Impacted products
Vendor Product Version
CP Plus KVMS Pro Version: 0   <
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T05:49:11.673Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-02"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2023-1518",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-01-16T20:30:49.308008Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-01-16T21:37:26.642Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "KVMS Pro",
          "vendor": "CP Plus",
          "versions": [
            {
              "lessThanOrEqual": "2.01.0.T.190521",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "user": "00000000-0000-4000-9000-000000000000",
          "value": "Harshit Shukla reported this vulnerability to CISA. "
        }
      ],
      "datePublic": "2023-03-23T20:44:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\nCP Plus KVMS Pro versions 2.01.0.T.190521 and prior are vulnerable to \nsensitive credentials being leaked because they are insufficiently \nprotected. \u0026nbsp; \n\n"
            }
          ],
          "value": "CP Plus KVMS Pro versions 2.01.0.T.190521 and prior are vulnerable to \nsensitive credentials being leaked because they are insufficiently \nprotected. \u00a0 \n\n"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-522",
              "description": "CWE-522 Insufficiently Protected Credentials",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2023-03-28T20:51:54.826Z",
        "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "shortName": "icscert"
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-02"
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      },
      "workarounds": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\nCP Plus has not responded to requests to work with CISA to mitigate this\n vulnerability. Users of the affected product are encouraged to contact \nCP Plus \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://www.cpplusworld.com/contact\"\u003ecustomer support\u003c/a\u003e\u0026nbsp;for additional information. \n\n\u003cbr\u003e"
            }
          ],
          "value": "CP Plus has not responded to requests to work with CISA to mitigate this\n vulnerability. Users of the affected product are encouraged to contact \nCP Plus  customer support https://www.cpplusworld.com/contact \u00a0for additional information. \n\n\n"
        }
      ],
      "x_generator": {
        "engine": "Vulnogram 0.1.0-dev"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
    "assignerShortName": "icscert",
    "cveId": "CVE-2023-1518",
    "datePublished": "2023-03-28T20:51:54.826Z",
    "dateReserved": "2023-03-20T14:41:24.074Z",
    "dateUpdated": "2025-01-16T21:37:26.642Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}