A Credential Exposure Vulnerability exists in the above-mentioned product and version. The vulnerability is due to using HTTP resulting in credentials being sent in clear text.
Fixes

Solution

Upgrade to v20.3.407


Workaround

No workaround given by the vendor.

History

Thu, 06 Feb 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jan 2025 18:30:00 +0000

Type Values Removed Values Added
Description A Credential Exposure Vulnerability exists in the above-mentioned product and version. The vulnerability is due to using HTTP resulting in credentials being sent in clear text.
Title PowerFlex® 755 Credential Exposure Vulnerability
Weaknesses CWE-319
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2025-02-06T21:26:17.072Z

Reserved: 2025-01-21T21:21:05.171Z

Link: CVE-2025-0631

cve-icon Vulnrichment

Updated: 2025-01-28T18:57:17.800Z

cve-icon NVD

Status : Received

Published: 2025-01-28T19:15:14.270

Modified: 2025-01-28T19:15:14.270

Link: CVE-2025-0631

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.