VulnerabilityModified
CVE-2022-29733
This vulnerability allows attackers to intercept HTTP Cookie authentication credentials via a man-in-the-middle attack.
MEDIUM 5.9EPSS 0.70%
Does this matter?
Lower severity and a low EPSS score (0.70%). Track it; it rarely justifies an emergency change on its own.
Description
Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to transmit and store sensitive information in cleartext. This vulnerability allows attackers to intercept HTTP Cookie authentication credentials via a man-in-the-middle attack.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.70% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- deltacontrols/entelitouch firmware
- Source
- cve@mitre.org
References
- https://www.deltacontrols.com/Vendor Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5704.phpExploit, Third Party Advisory
- https://www.deltacontrols.com/Vendor Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5704.phpExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.