Vulnerability Description
The access control in CemiPark software stores integration (e.g. FTP or SIP) credentials in plain-text. An attacker who gained unauthorized access to the device can retrieve clear text passwords used by the system.This issue affects CemiPark software: 4.5, 4.7, 5.03 and potentially others. The vendor refused to provide the specific range of affected products.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- http://cemi.pl/
- https://cert.pl/en/posts/2024/05/CVE-2024-4423/
- https://cert.pl/posts/2024/05/CVE-2024-4423/
- http://cemi.pl/
- https://cert.pl/en/posts/2024/05/CVE-2024-4423/
- https://cert.pl/posts/2024/05/CVE-2024-4423/
FAQ
What is CVE-2024-4425?
CVE-2024-4425 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The access control in CemiPark software stores integration (e.g. FTP or SIP) credentials in plain-text. An attacker who gained unauthorized access to the device can retrieve clear text passwords used ...
How severe is CVE-2024-4425?
CVE-2024-4425 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-4425?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.