Home
MEDIUM: 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
1.0.0.0 (semver) before 4.10.0.0
affected
Description
The affected product may expose credentials remotely between low privileged visualization users during concurrent login operations due to insufficient isolation of authentication data. The vulnerability affects only login operations within an active visualization session.
Problem types
CWE-522 Insufficiently Protected Credentials
Product status
1.0.0.0 (semver) before 4.10.0.0
Credits
Silvan Schweizer from CTA AG
References
codesys.csaf-tp.certvde.com/...sory2026-07_vde-2026-052.json