VulnerabilityModified
CVE-2017-14009
An Information Exposure issue was discovered in ProMinent MultiFLEX M10a Controller web interface.
MEDIUM 6.5EPSS 0.73%
Does this matter?
Lower severity and a low EPSS score (0.73%). Track it; it rarely justifies an emergency change on its own.
Description
An Information Exposure issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When an authenticated user uses the Change Password feature on the application, the current password for the user is specified in plaintext. This may allow an attacker who has been authenticated to gain access to the password.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.73% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-319
- Affected
- prominent/multiflex m10a controller firmware
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/101259Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-285-01Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/101259Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-285-01Mitigation, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.