SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-14009

An Information Exposure issue was discovered in ProMinent MultiFLEX M10a Controller web interface.

MEDIUM 6.5EPSS 0.73%

Does this matter?

Lower severity and a low EPSS score (0.73%). Track it; it rarely justifies an emergency change on its own.

Description

An Information Exposure issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When an authenticated user uses the Change Password feature on the application, the current password for the user is specified in plaintext. This may allow an attacker who has been authenticated to gain access to the password.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.73% probability · 52th percentile
CISA KEV
Not listed
Weakness
CWE-200, CWE-319
Affected
prominent/multiflex m10a controller firmware
Source
ics-cert@hq.dhs.gov

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.