The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belonging to legitimate users
Advisories
Source ID Title
EUVD EUVD EUVD-2022-34822 The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belonging to legitimate users
Fixes

Solution

PcVue 12: The fix is available in Maintenance release 12.0.27 After installing the fix, users should update the Web Deployment Console (WDC) and re-deploy the Web Server. All users using the affected component should install a patched release of the WDC and re-deploy the Web Server. This will allow the WDC to update and protect the database connection string, including clearing any sensitive information stored in the web.config file.


Workaround

ARC Informatique has identified additional steps users can apply to reduce the risk: Uninstall the Web Server All users not using the affected component should uninstall the web server. The OAuth web service and its configuration are part of the Web Server for PcVue. If the system does not require Web & Mobile features, then users should not install them. Users should contact ARC Informatique’s PcVue Solutions for assistance with the above steps. For additional information, visit the public ARC Informatique security alert page.

History

Wed, 16 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-04-16T16:11:59.819Z

Reserved: 2022-07-28T00:00:00.000Z

Link: CVE-2022-2569

cve-icon Vulnrichment

Updated: 2024-08-03T00:39:08.065Z

cve-icon NVD

Status : Modified

Published: 2022-08-24T16:15:11.907

Modified: 2024-11-21T07:01:16.057

Link: CVE-2022-2569

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.