GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the passwords and gain privileges.
Threat-Mapped Scoring
Score: 0.0
Priority: Unclassified
EPSS
Score: 0.03726 Percentile:
0.87497
CVSS Scoring
CVSS v3.1 Score: 9.8
Severity: CRITICAL
Mapped CWE(s)
CWE-312
: Cleartext Storage of Sensitive Information
All CAPEC(s)
CAPEC-37: Retrieve Embedded Sensitive Data
CAPEC(s) with Mapped TTPs
CAPEC-37: Retrieve Embedded Sensitive Data
Mapped TTPs: