Home
MEDIUM: 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:NDefault status
unaffected
VC:00 (semver) before VC:07
affected
Default status
unaffected
VC:00 (semver) before VC:07
affected
Default status
unaffected
VC:00 (semver) before VC:07
affected
Default status
unaffected
VC:00 (semver) before VC:07
affected
Description
An unauthenticated remote attacker (MITM) can intercept the websocket messages to gain access to the login credentials for the Webfrontend.
Problem types
CWE-523 Unprotected Transport of Credentials
Product status
VC:00 (semver) before VC:07
VC:00 (semver) before VC:07
VC:00 (semver) before VC:07
VC:00 (semver) before VC:07
Credits
D. Blagojevic, S. Dietz, F. Koroknai, T. Weber from CyberDanube Security Research
References
seclists.org/fulldisclosure/2025/Oct/12
certvde.com/de/advisories/VDE-2025-072