HMS Networks EWON FLEXY 202 Insufficiently Protected Credentials

CVE Details

Basic Information

Title HMS Networks EWON FLEXY 202 Insufficiently Protected Credentials
Type cve
Published 2024-10-17T18:13:52.552Z
Modified 2024-10-17T19:22:56.932Z

Product Information

Vendor HMS Networks
Product EWON FLEXY 202
Version 14.2s0

CVSS Information

Base Score 7.1 (HIGH)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N

AI Analysis

AI Description The EWON FLEXY 202 device uses a weak base64 encoding method to transmit credentials, making it vulnerable to interception by attackers who can decode the credentials.
AI Severity High
AI Vendor HMS Networks
AI Product EWON FLEXY 202
AI Version 14.2s0

Affected Products

  • HMS Networks EWON FLEXY 202 14.2s0

Additional Information

CWE List CWE-522
Source icscert

Description

The EWON FLEXY 202 transmits credentials using a weak encoding method base64. An attacker who is present in the network can sniff the traffic and decode the credentials.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.