VulnerabilityModified
CVE-2022-4311
An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2.
MEDIUM 6.5EPSS 0.33%
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users unauthorized access to the underlying data sources.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- arcinfo/pcvue
- Source
- ics-cert@hq.dhs.gov
References
- https://www.pcvuesolutions.com/support/index.php/en/security-bulletin/1165-security-bulletin-2022-6Permissions Required, Vendor Advisory
- https://www.pcvuesolutions.com/support/index.php/en/security-bulletin/1165-security-bulletin-2022-6Permissions Required, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.