MEDIUM · 5.9

CVE-2022-29733

Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to transmit and store sensitive information in cleartext. This vulnerability allows attackers to intercept HTTP Cookie aut...

Vulnerability Description

Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to transmit and store sensitive information in cleartext. This vulnerability allows attackers to intercept HTTP Cookie authentication credentials via a man-in-the-middle attack.

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
DeltacontrolsEntelitouch Firmware3.33.4005
DeltacontrolsEntelitouch-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-29733?

CVE-2022-29733 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to transmit and store sensitive information in cleartext. This vulnerability allows attackers to intercept HTTP Cookie aut...

How severe is CVE-2022-29733?

CVE-2022-29733 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-29733?

Check the references section above for vendor advisories and patch information. Affected products include: Deltacontrols Entelitouch Firmware, Deltacontrols Entelitouch.