cve/2022/CVE-2022-40693.md

18 lines
906 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2022-40693](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40693)
![](https://img.shields.io/static/v1?label=Product&message=SDS-3008%20Series%20Industrial%20Ethernet%20Switch&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%202.1%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-319%3A%20Cleartext%20Transmission%20of%20Sensitive%20Information&color=brighgreen)
### Description
A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.
### POC
#### Reference
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1616
#### Github
No PoCs found on GitHub currently.