Vulnerability Details CVE-2022-21184
An information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise 3.5.4, 3.6 and 3.7. A plaintext HTTP request can lead to a disclosure of login credentials. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.3%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 4.3
Products affected by CVE-2022-21184
-
cpe:2.3:a:atvise:atvise:3.5.4
-
cpe:2.3:a:atvise:atvise:3.6
-
cpe:2.3:a:atvise:atvise:3.7