Impact
The vulnerability arises from insufficient isolation of authentication data within CODESYS Visualization, allowing credentials to be exposed between low privileged users during concurrent login operations in an active session. This flaw leads to the disclosure of user credentials, enabling an attacker who can trigger such logins to gain unauthorized access to other accounts, corresponding to CWE‑522.
Affected Systems
Affected vendor and product are CODESYS: Visualization. No specific product versions or build numbers are listed in the advisory, so all releases remain potentially susceptible until an official patch is applied.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests there is no known mass exploitation. The likely attack vector is a remote authenticated user who logs into the visualization session and manually initiates concurrent logins, thereby leaking credentials to another low privileged user; this is inferred from the description of concurrent login operations within an active session.
OpenCVE Enrichment