vendor:
enteliTOUCH
by:
LiquidWorm
7.5
CVSS
HIGH
Cookie User Password Disclosure
200
CWE
Product Name: enteliTOUCH
Affected Version From: 3.33.4005
Affected Version To: 3.40.3935
Patch Exists: NO
Related CWE:
CPE: delta_controls:entelitouch:3.40.3935
Platforms Tested: DELTA enteliTOUCH
2022
Delta Controls enteliTOUCH 3.40.3935 – Cookie User Password Disclosure
The application suffers from a cleartext transmission/storage of sensitive information in a Cookie. This allows a remote attacker to intercept the HTTP Cookie authentication credentials through a man-in-the-middle attack.
Mitigation:
Encrypt or hash the sensitive information stored in the Cookie to prevent cleartext transmission/storage.