PT-2022-3482 · Unknown · Data Center Expert

CVE-2022-32519

·

Published

2022-06-14

·

Updated

2023-02-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Data Center Expert versions prior to V7.9.0
Description A vulnerability exists where passwords are stored in a recoverable format, potentially allowing unwanted access to a Data Center Expert instance over a network by a malicious third-party. This could result in a malicious actor gaining full control over the software.
Recommendations For versions prior to V7.9.0, update to version V7.9.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Data Center Expert instance to minimize the risk of exploitation.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04261
CVE-2022-32519

Affected Products

Data Center Expert