Description
An unauthenticated remote attacker (MITM) can intercept the websocket messages to gain access to the login credentials for the Webfrontend.
Problem types
CWE-523 Unprotected Transport of Credentials
Product status
VC:00 before VC:07
VC:00 before VC:07
VC:00 before VC:07
VC:00 before VC:07
Credits
D. Blagojevic, S. Dietz, F. Koroknai, T. Weber from CyberDanube Security Research
References
certvde.com/de/advisories/VDE-2025-072