// For flags

CVE-2014-0347

 

Severity Score

3.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix 31, and Web Security Gateway Anywhere 7.7.3 before Hotfix 31 allows remote authenticated users to read cleartext passwords by replacing type="password" with type="text" in an INPUT element in the (1) Log Database or (2) User Directories component.

El módulo de configuraciones en Websense Triton Unified Security Center 7.7.3 anterior a Hotfix 31, Web Filter 7.7.3 anterior a Hotfix 31, Web Security 7.7.3 anterior a Hotfix 31, Web Security Gateway 7.7.3 anterior a Hotfix 31 y Web Security Gateway Anywhere 7.7.3 anterior a Hotfix 31 permite a usuarios remotos autenticados leer contraseñas en texto claro mediante la sustitución type="password" con type="text" en un elemento INPUT en el componente (1) Log Database o (2) User Directories.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-12-05 CVE Reserved
  • 2014-04-12 CVE Published
  • 2024-02-23 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-255: Credentials Management Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Websense
Search vendor "Websense"
Triton Unified Security Center
Search vendor "Websense" for product "Triton Unified Security Center"
7.7.3
Search vendor "Websense" for product "Triton Unified Security Center" and version "7.7.3"
-
Affected
Websense
Search vendor "Websense"
Triton Web Filter
Search vendor "Websense" for product "Triton Web Filter"
7.7.3
Search vendor "Websense" for product "Triton Web Filter" and version "7.7.3"
-
Affected
Websense
Search vendor "Websense"
Triton Web Security
Search vendor "Websense" for product "Triton Web Security"
7.7.3
Search vendor "Websense" for product "Triton Web Security" and version "7.7.3"
-
Affected
Websense
Search vendor "Websense"
Triton Web Security Gateway
Search vendor "Websense" for product "Triton Web Security Gateway"
7.7.3
Search vendor "Websense" for product "Triton Web Security Gateway" and version "7.7.3"
-
Affected
Websense
Search vendor "Websense"
Triton Web Security Gateway Anywhere
Search vendor "Websense" for product "Triton Web Security Gateway Anywhere"
7.7.3
Search vendor "Websense" for product "Triton Web Security Gateway Anywhere" and version "7.7.3"
-
Affected